<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Self-Hosted - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/self-hosted/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 20:22:51 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/self-hosted/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Trigger.dev SSRF via Unvalidated Webhook Delivery URLs</title><link>https://feed.craftedsignal.io/briefs/2026-10-trigger-dev-ssrf/</link><pubDate>Fri, 02 Oct 2026 20:22:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-trigger-dev-ssrf/</guid><description>An authenticated user can configure malicious webhook endpoints in Trigger.dev (&lt; 4.5.2) to perform server-side request forgery (SSRF) against internal services and cloud metadata endpoints.</description><content:encoded><![CDATA[<p>Trigger.dev versions prior to 4.5.2 contain a critical server-side request forgery (SSRF) vulnerability. The application allows authenticated organization members to configure webhook alert channels with arbitrary delivery URLs. These URLs are stored as unvalidated strings and are subsequently fetched by the Trigger.dev control plane to deliver alerts using POST requests.</p>
<p>The application lacks any validation mechanism - such as host blocklists for private IP ranges, loopback addresses (127.0.0.1), or link-local addresses (e.g., 169.254.169.254) - at the time of creation or during the alert delivery process. An attacker with low-privilege organization access can supply an internal-only URL, causing the server to proxy signed POST requests to internal services or cloud IMDS endpoints. Because the requests include valid HMAC signatures computed by the platform, they may bypass internal authentication logic that relies on these signatures, resulting in potential unauthorized command execution or data exfiltration from internal APIs.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker authenticates to a Trigger.dev instance using a valid user account.</li>
<li>Attacker invokes the project API endpoint <code>/api/v1/projects/&lt;projectRef&gt;/alertChannels</code>.</li>
<li>Attacker submits a POST request containing a malicious <code>channelData</code> payload where the <code>url</code> points to an internal resource (e.g., <code>http://169.254.169.254/latest/meta-data/</code>).</li>
<li>The application saves the malicious URL to the <code>ProjectAlert</code> model without validating the hostname or IP range.</li>
<li>Attacker triggers a task run failure event within their controlled environment.</li>
<li>The <code>deliverAlert</code> service fetches the stored webhook URL, triggering a server-side request to the target internal IP.</li>
<li>The target internal service receives the signed POST request, potentially treating it as a legitimate system-originated event.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an attacker to interact with services reachable from the Trigger.dev control plane, including internal management APIs, cloud instance metadata services (IMDS), and other local network resources. This can result in credential theft, internal data exposure, or the unauthorized manipulation of internal service configurations that rely on the HMAC headers provided by the Trigger.dev platform.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Trigger.dev to version 4.5.2 or later immediately to incorporate input validation for webhook URLs.</li>
<li>Implement an egress filtering or proxy layer on the network hosting the Trigger.dev control plane to block outbound traffic to private (RFC 1918), loopback, and link-local address spaces.</li>
<li>Audit application logs for suspicious webhook alert channel creation events targeting non-public IP addresses.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authorization-bypass</category><category>insecure-design</category><category>cloud-security</category><category>web-vulnerability</category><category>self-hosted</category><category>authentication-bypass</category><category>idor</category><category>broken-access-control</category><category>web-application</category></item></channel></rss>