{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3atriggertrigger.dev/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:trigger:trigger.dev:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-85651"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Trigger.dev (\u003c 4.5.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Trigger.dev"],"content_html":"\u003cp\u003eTrigger.dev versions before 4.5.2 are affected by an improper authorization vulnerability in the platform's run replay functionality. The flaw stems from a failure to correctly validate environment membership when a user initiates a replay operation. An authenticated attacker can exploit this weakness to inject task runs into environments or organizations they do not belong to.\u003c/p\u003e\n\u003cp\u003eThis vulnerability allows for unauthorized resource consumption and the potential to pollute the run history logs of victim projects. Because the replay mechanism executes under the context of the target environment, it could lead to sensitive data processing or unintended side effects if the replayed task logic interacts with external systems configured in the target environment. Organizations using Trigger.dev should prioritize updating to version 4.5.2 or later to ensure that cross-environment replay operations are properly restricted.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to manipulate task execution flows across organizational boundaries. The impact includes unauthorized consumption of compute resources, potential injection of malicious task inputs into victim workflows, and degradation of log integrity. This vulnerability affects all self-hosted and cloud-managed instances of Trigger.dev running versions below 4.5.2.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Trigger.dev deployments to version 4.5.2 or later to resolve the authorization logic error associated with CVE-2026-85651.\u003c/li\u003e\n\u003cli\u003eAudit application logs for abnormal \u0026quot;replay\u0026quot; API calls originating from authenticated users that reference unexpected organization or environment identifiers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T17:26:45Z","date_published":"2026-09-04T17:26:45Z","id":"https://feed.craftedsignal.io/briefs/2026-09-trigger-dev-auth-bypass/","summary":"Trigger.dev versions prior to 4.5.2 contain an improper authorization vulnerability that allows authenticated attackers to inject task runs into arbitrary environments.","title":"Authorization Bypass in Trigger.dev Run Replay Operation","url":"https://feed.craftedsignal.io/briefs/2026-09-trigger-dev-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:trigger:trigger.dev:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}