CVE ReportsGHSA-QXPP-QJG8-X4JV: Cross-Tenant Run Replay and Task Injection in...
Vulnerability ID: GHSA-QXPP-QJG8-X4JV
CVSS Score: 9.9
Published: 2026-10-02
A critical Broken Object Level Authorization (BOLA) vulnerability was identified in Trigger.dev before version v4.5.2. An authenticated attacker could trigger a run replay and supply an arbitrary target environmentId belonging to a completely different tenant. Because the server failed to validate whether the target environment belonged to the same project or organization as the source run, it would execute the task within the victim's environment, resulting in unauthorized cross-tenant write operations and remote task execution.
Authenticated attackers can execute tasks inside other tenants' environments by specifying a foreign environmentId during task replay, bypassing tenant isolation.
4.5.2)Ensure replay run target environment matches the source task run project
Remediation Steps:
Read the full report for GHSA-QXPP-QJG8-X4JV on our website for more details including interactive diagrams and full exploit analysis.