VYPR
Vendor

Triggerdotdev

Products
2
CVEs
9
Across products
10
Status
Private

Products

2

Recent CVEs

9
  • CVE-2026-73656CriAug 13, 2026
    risk 0.57cvss 9.9epss 0.01

    Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/v3/services/createDeploymentBackgroundWo…

  • CVE-2026-85651HigSep 4, 2026
    risk 0.48cvss 8.5epss 0.00

    Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to…

  • CVE-2026-73654HigAug 13, 2026
    risk 0.48cvss 8.5epss 0.01

    Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the PUT /api/v1/runs/:runId/metadata endpoint passes attacker-controlled operation.key values to new JSONHeroPath(operation.key).set(newMetadata, value) in…

  • CVE-2026-73659HigAug 13, 2026
    risk 0.46cvss 8.1epss 0.01

    Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.$.ts pass a caller-controlled filename through resolveStoreProtocolForPacketPresign to generatePresignedUrl…

  • CVE-2026-73658HigAug 13, 2026
    risk 0.46cvss 8.2epss 0.00

    Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-controlled packet keys to URL.pathname,…

  • CVE-2026-73655HigAug 13, 2026
    risk 0.41cvss 7.4epss 0.00

    Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() in apps/webapp/app/models/user.server.ts…

  • CVE-2026-92773HigSep 16, 2026
    risk 0.39cvss 7.1epss 0.00

    Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying state cookies and supplying sequential installation…

  • CVE-2026-85650MedSep 4, 2026
    risk 0.28cvss 5.4epss 0.00

    Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert channels with URLs targeting internal…

  • CVE-2026-73657MedAug 13, 2026
    risk 0.20cvss 4.2epss 0.00

    Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp/app/routes/api.v1.runs.$runParam.replay.ts uses `prisma.taskRun.findUnique({ where: { friendlyId: runParam…

VYPR — Vulnerability Intelligence