{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/self-hosted/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["trigger.dev (\u003c 4.5.2)","trigger.dev (\u003c= 4.5.5)","trigger.dev (\u003c= 4.5.1)"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","insecure-design","cloud-security","web-vulnerability","self-hosted","authentication-bypass","idor","broken-access-control","web-application"],"_cs_type":"advisory","_cs_vendors":["Trigger.dev"],"content_html":"\u003cp\u003eTrigger.dev versions prior to 4.5.2 contain a critical server-side request forgery (SSRF) vulnerability. The application allows authenticated organization members to configure webhook alert channels with arbitrary delivery URLs. These URLs are stored as unvalidated strings and are subsequently fetched by the Trigger.dev control plane to deliver alerts using POST requests.\u003c/p\u003e\n\u003cp\u003eThe application lacks any validation mechanism - such as host blocklists for private IP ranges, loopback addresses (127.0.0.1), or link-local addresses (e.g., 169.254.169.254) - at the time of creation or during the alert delivery process. An attacker with low-privilege organization access can supply an internal-only URL, causing the server to proxy signed POST requests to internal services or cloud IMDS endpoints. Because the requests include valid HMAC signatures computed by the platform, they may bypass internal authentication logic that relies on these signatures, resulting in potential unauthorized command execution or data exfiltration from internal APIs.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to a Trigger.dev instance using a valid user account.\u003c/li\u003e\n\u003cli\u003eAttacker invokes the project API endpoint \u003ccode\u003e/api/v1/projects/\u0026lt;projectRef\u0026gt;/alertChannels\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker submits a POST request containing a malicious \u003ccode\u003echannelData\u003c/code\u003e payload where the \u003ccode\u003eurl\u003c/code\u003e points to an internal resource (e.g., \u003ccode\u003ehttp://169.254.169.254/latest/meta-data/\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe application saves the malicious URL to the \u003ccode\u003eProjectAlert\u003c/code\u003e model without validating the hostname or IP range.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a task run failure event within their controlled environment.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003edeliverAlert\u003c/code\u003e service fetches the stored webhook URL, triggering a server-side request to the target internal IP.\u003c/li\u003e\n\u003cli\u003eThe target internal service receives the signed POST request, potentially treating it as a legitimate system-originated event.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to interact with services reachable from the Trigger.dev control plane, including internal management APIs, cloud instance metadata services (IMDS), and other local network resources. This can result in credential theft, internal data exposure, or the unauthorized manipulation of internal service configurations that rely on the HMAC headers provided by the Trigger.dev platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Trigger.dev to version 4.5.2 or later immediately to incorporate input validation for webhook URLs.\u003c/li\u003e\n\u003cli\u003eImplement an egress filtering or proxy layer on the network hosting the Trigger.dev control plane to block outbound traffic to private (RFC 1918), loopback, and link-local address spaces.\u003c/li\u003e\n\u003cli\u003eAudit application logs for suspicious webhook alert channel creation events targeting non-public IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T22:50:46Z","date_published":"2026-10-02T20:22:51Z","id":"https://feed.craftedsignal.io/briefs/2026-10-trigger-dev-ssrf/","summary":"An authenticated user can configure malicious webhook endpoints in Trigger.dev (\u003c 4.5.2) to perform server-side request forgery (SSRF) against internal services and cloud metadata endpoints.","title":"Trigger.dev SSRF via Unvalidated Webhook Delivery URLs","url":"https://feed.craftedsignal.io/briefs/2026-10-trigger-dev-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Self-Hosted","version":"https://jsonfeed.org/version/1.1"}