<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:trigger:trigger.dev:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3atriggertrigger.dev/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 04 Sep 2026 17:26:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3atriggertrigger.dev/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in Trigger.dev Run Replay Operation</title><link>https://feed.craftedsignal.io/briefs/2026-09-trigger-dev-auth-bypass/</link><pubDate>Fri, 04 Sep 2026 17:26:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-trigger-dev-auth-bypass/</guid><description>Trigger.dev versions prior to 4.5.2 contain an improper authorization vulnerability that allows authenticated attackers to inject task runs into arbitrary environments.</description><content:encoded><![CDATA[<p>Trigger.dev versions before 4.5.2 are affected by an improper authorization vulnerability in the platform's run replay functionality. The flaw stems from a failure to correctly validate environment membership when a user initiates a replay operation. An authenticated attacker can exploit this weakness to inject task runs into environments or organizations they do not belong to.</p>
<p>This vulnerability allows for unauthorized resource consumption and the potential to pollute the run history logs of victim projects. Because the replay mechanism executes under the context of the target environment, it could lead to sensitive data processing or unintended side effects if the replayed task logic interacts with external systems configured in the target environment. Organizations using Trigger.dev should prioritize updating to version 4.5.2 or later to ensure that cross-environment replay operations are properly restricted.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows attackers to manipulate task execution flows across organizational boundaries. The impact includes unauthorized consumption of compute resources, potential injection of malicious task inputs into victim workflows, and degradation of log integrity. This vulnerability affects all self-hosted and cloud-managed instances of Trigger.dev running versions below 4.5.2.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all Trigger.dev deployments to version 4.5.2 or later to resolve the authorization logic error associated with CVE-2026-85651.</li>
<li>Audit application logs for abnormal &quot;replay&quot; API calls originating from authenticated users that reference unexpected organization or environment identifiers.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>