{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/github-integration/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:trigger:trigger.dev:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-92773"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Trigger.dev (\u003c 4.6.0)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","github-integration","cloud-native"],"_cs_type":"advisory","_cs_vendors":["Trigger.dev"],"content_html":"\u003cp\u003eTrigger.dev versions prior to 4.6.0 contain a critical vulnerability related to how the platform validates the ownership of GitHub App installations during the binding process. The vulnerability stems from a failure to verify that an authenticated user actually controls or owns the GitHub App installation before associating it with their organization within the Trigger.dev platform.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this flaw by leveraging sequential installation identifiers combined with the replay of state cookies. By predicting or brute-forcing installation IDs and interacting with the authorization flow, an attacker can trick the system into binding a victim's GitHub App installation to the attacker's own organization. This results in the attacker gaining unauthorized access to the victim's GitHub repositories, effectively achieving account and resource takeover. This flaw represents a significant risk for organizations using Trigger.dev for workflow automation, as it allows for unauthorized access to sensitive source code and environment secrets.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthorized access to GitHub repositories belonging to other users or organizations. If exploited, an attacker can gain the permissions granted to the hijacked GitHub App installation, potentially allowing for the theft of source code, environment secrets, or the manipulation of CI/CD pipelines connected to Trigger.dev.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of Trigger.dev to version 4.6.0 or later to address the underlying authentication logic flaw in the GitHub App installation binding process.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Trigger.dev to version 4.6.0 or later immediately to patch CVE-2026-92773.\u003c/li\u003e\n\u003cli\u003eAudit existing GitHub App installations within the Trigger.dev dashboard for any unknown or unauthorized organization associations.\u003c/li\u003e\n\u003cli\u003eReview GitHub App permissions granted to the Trigger.dev integration to ensure minimal privilege is applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T21:55:49Z","date_published":"2026-09-16T21:55:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-trigger-dev-auth-bypass/","summary":"Trigger.dev versions before 4.6.0 contain an authentication bypass vulnerability allowing attackers to hijack GitHub App installations and gain unauthorized repository access by manipulating state cookies and installation identifiers.","title":"Authentication Bypass in Trigger.dev via GitHub App Installation Binding","url":"https://feed.craftedsignal.io/briefs/2026-09-trigger-dev-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Github-Integration","version":"https://jsonfeed.org/version/1.1"}