High severity8.5NVD Advisory· Published Sep 4, 2026
CVE-2026-85651
CVE-2026-85651
Description
Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to consume victim resources and pollute run history.
Affected products
1- Range: <4.5.2
Patches
Vulnerability mechanics
References
5- github.com/triggerdotdev/trigger.dev/commit/34b1a181c2a1d33a53ebab88f84b05f81fea4254nvd
- github.com/triggerdotdev/trigger.dev/issues/4173nvd
- github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.2nvd
- github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-qxpp-qjg8-x4jvnvd
- www.vulncheck.com/advisories/trigger-dev-before-4.5.2-unauthorized-environment-access-via-run-replaynvd
News mentions
0No linked articles in our index yet.