CVE-2026-85651
moderateMissing Authorization in Trigger.dev Run Replay Enables Cross-Environment Run Injection
Trigger.dev versions before 4.5.2 fail to verify environment membership (CWE-862, missing authorization) during run replay operations, so an authenticated attacker can replay runs into environments belonging to other organizations or projects. The attack is triggered over the network by a low-privileged authenticated user and requires no user interaction or special conditions. The attacker gains the ability to inject their own task runs into victims' environments, consuming victim compute resources and polluting run history, which drives the high integrity and low availability impact reflected in the 8.4 CVSS 4.0 score. Any Trigger.dev deployment (self-hosted or cloud) running a version prior to 4.5.2 is affected. Exploitation has not been observed: there is no known public proof-of-concept, EPSS is 0.3%, and the issue is not in CISA KEV.
What to do: Upgrade Trigger.dev to 4.5.2 or later, which adds environment membership validation on replay. Until patched, restrict replay capabilities to trusted users and review run history for unexpected runs injected into other organizations' or projects' environments.
| Trigger.dev | all versions before 4.5.2 (< 4.5.2) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to consume victim resources and pollute run history.
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.