ZeroHour

CVE-2026-85651

moderate

Missing Authorization in Trigger.dev Run Replay Enables Cross-Environment Run Injection

CVSS 4.0
8.4 high
EPSS
<1%p19
Published
()
Modified
AI analysis

Trigger.dev versions before 4.5.2 fail to verify environment membership (CWE-862, missing authorization) during run replay operations, so an authenticated attacker can replay runs into environments belonging to other organizations or projects. The attack is triggered over the network by a low-privileged authenticated user and requires no user interaction or special conditions. The attacker gains the ability to inject their own task runs into victims' environments, consuming victim compute resources and polluting run history, which drives the high integrity and low availability impact reflected in the 8.4 CVSS 4.0 score. Any Trigger.dev deployment (self-hosted or cloud) running a version prior to 4.5.2 is affected. Exploitation has not been observed: there is no known public proof-of-concept, EPSS is 0.3%, and the issue is not in CISA KEV.

What to do: Upgrade Trigger.dev to 4.5.2 or later, which adds environment membership validation on replay. Until patched, restrict replay capabilities to trusted users and review run history for unexpected runs injected into other organizations' or projects' environments.

Affected
Trigger.devall versions before 4.5.2 (< 4.5.2)
Estimated exposure
moderatelikely low thousands of deployments (self-hosted instances and cloud workspaces); exact count unknown — Trigger.dev is a niche open-source job-orchestration platform typically adopted by small engineering teams, with no published install metrics, so exposure is estimated from its modest developer-tool deployment footprint.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to consume victim resources and pollute run history.

Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.