GHSA-QXPP-QJG8-X4JV: GHSA-QXPP-QJG8-X4JV: Cross-Tenant Run Replay and Task Injection in Trigger.dev

# security# cve# cybersecurity# ghsa
GHSA-QXPP-QJG8-X4JV: GHSA-QXPP-QJG8-X4JV: Cross-Tenant Run Replay and Task Injection in Trigger.devCVE Reports

GHSA-QXPP-QJG8-X4JV: Cross-Tenant Run Replay and Task Injection in...

GHSA-QXPP-QJG8-X4JV: Cross-Tenant Run Replay and Task Injection in Trigger.dev

Vulnerability ID: GHSA-QXPP-QJG8-X4JV
CVSS Score: 9.9
Published: 2026-10-02

A critical Broken Object Level Authorization (BOLA) vulnerability was identified in Trigger.dev before version v4.5.2. An authenticated attacker could trigger a run replay and supply an arbitrary target environmentId belonging to a completely different tenant. Because the server failed to validate whether the target environment belonged to the same project or organization as the source run, it would execute the task within the victim's environment, resulting in unauthorized cross-tenant write operations and remote task execution.

TL;DR

Authenticated attackers can execute tasks inside other tenants' environments by specifying a foreign environmentId during task replay, bypassing tenant isolation.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-639 / CWE-285
  • Attack Vector: Network
  • CVSS v3.1 Score: 9.9 (Critical)
  • Exploit Status: poc
  • KEV Status: Not Listed
  • Vulnerability Class: Broken Object Level Authorization (BOLA)

Affected Systems

  • Trigger.dev Self-Hosted Web Application
  • Trigger.dev Cloud Services (prior to v4.5.2)
  • Trigger.dev: < 4.5.2 (Fixed in: 4.5.2)

Code Analysis

Commit: 34b1a18

Ensure replay run target environment matches the source task run project

Exploit Details

Mitigation Strategies

  • Upgrade Trigger.dev self-hosted instances to version v4.5.2 or later
  • Restrict API access via network firewalls and limit authorization tokens
  • Monitor application logs for unauthorized replay attempts

Remediation Steps:

  1. Identify all deployed self-hosted instances of Trigger.dev
  2. Pull the official v4.5.2 Docker image or update repository dependencies to v4.5.2
  3. Deploy the updated application to your cluster or host environment
  4. Verify the fix by testing cross-project task replay using non-matching environment IDs
  5. Scan application logs for any occurrences of the block signature 'Refusing to replay a run into an environment outside its project'

References


Read the full report for GHSA-QXPP-QJG8-X4JV on our website for more details including interactive diagrams and full exploit analysis.