PT-2026-71810 · Unknown · Trigger.Dev

CVE-2026-73654

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Trigger.dev versions 3.3.8 through 4.5.5
Description The PUT '/api/v1/runs/:runId/metadata' endpoint fails to reject dangerous constructor and prototype path segments when passing operation.key values to the JSONHeroPath().set() function. This allows a user with a standard environment API key to perform prototype pollution on Object.prototype within the shared webapp process. This can lead to the corruption of Prisma queries and Prometheus labels, disruption of worker authentication for other tenants, and a process-wide denial of service.
Recommendations Update Trigger.dev to version 4.5.6.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73654
GHSA-P28V-F755-9QRG

Affected Products

Trigger.Dev