CVE-2026-85651

high

Description

Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to consume victim resources and pollute run history.

References

https://www.vulncheck.com/advisories/trigger-dev-before-4.5.2-unauthorized-environment-access-via-run-replay

https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-qxpp-qjg8-x4jv

https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.2

https://github.com/triggerdotdev/trigger.dev/issues/4173

https://github.com/triggerdotdev/trigger.dev/commit/34b1a181c2a1d33a53ebab88f84b05f81fea4254

https://github.com/triggerdotdev/trigger.dev

Details

Source: Mitre, NVD

Published: 2026-09-04

Updated: 2026-09-10

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:P

Severity: High

CVSS v3

Base Score: 8.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

Severity: High

CVSS v4

Base Score: 8.4

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L

Severity: High

EPSS

EPSS: 0.00269