<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Trigger.dev (&lt; 4.6.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/trigger.dev--4.6.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 21:55:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/trigger.dev--4.6.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in Trigger.dev via GitHub App Installation Binding</title><link>https://feed.craftedsignal.io/briefs/2026-09-trigger-dev-auth-bypass/</link><pubDate>Wed, 16 Sep 2026 21:55:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-trigger-dev-auth-bypass/</guid><description>Trigger.dev versions before 4.6.0 contain an authentication bypass vulnerability allowing attackers to hijack GitHub App installations and gain unauthorized repository access by manipulating state cookies and installation identifiers.</description><content:encoded><![CDATA[<p>Trigger.dev versions prior to 4.6.0 contain a critical vulnerability related to how the platform validates the ownership of GitHub App installations during the binding process. The vulnerability stems from a failure to verify that an authenticated user actually controls or owns the GitHub App installation before associating it with their organization within the Trigger.dev platform.</p>
<p>An attacker can exploit this flaw by leveraging sequential installation identifiers combined with the replay of state cookies. By predicting or brute-forcing installation IDs and interacting with the authorization flow, an attacker can trick the system into binding a victim's GitHub App installation to the attacker's own organization. This results in the attacker gaining unauthorized access to the victim's GitHub repositories, effectively achieving account and resource takeover. This flaw represents a significant risk for organizations using Trigger.dev for workflow automation, as it allows for unauthorized access to sensitive source code and environment secrets.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows unauthorized access to GitHub repositories belonging to other users or organizations. If exploited, an attacker can gain the permissions granted to the hijacked GitHub App installation, potentially allowing for the theft of source code, environment secrets, or the manipulation of CI/CD pipelines connected to Trigger.dev.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the upgrade of Trigger.dev to version 4.6.0 or later to address the underlying authentication logic flaw in the GitHub App installation binding process.</p>
<ul>
<li>Upgrade Trigger.dev to version 4.6.0 or later immediately to patch CVE-2026-92773.</li>
<li>Audit existing GitHub App installations within the Trigger.dev dashboard for any unknown or unauthorized organization associations.</li>
<li>Review GitHub App permissions granted to the Trigger.dev integration to ensure minimal privilege is applied.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authentication-bypass</category><category>github-integration</category><category>cloud-native</category></item></channel></rss>