VYPR

Trigger.dev

by Triggerdotdev

Source repositories

CVEs (1)

  • CVE-2026-92773HigSep 16, 2026
    risk 0.39cvss 7.1epss

    Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying state cookies and supplying sequential installation…