PT-2026-71810 · Unknown · Trigger.Dev
CVE-2026-73654
·
Published
2026-08-13
·
Updated
2026-08-13
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Trigger.dev versions 3.3.8 through 4.5.5
Description
The PUT '/api/v1/runs/:runId/metadata' endpoint fails to reject dangerous constructor and prototype path segments when passing
operation.key values to the JSONHeroPath().set() function. This allows a user with a standard environment API key to perform prototype pollution on Object.prototype within the shared webapp process. This can lead to the corruption of Prisma queries and Prometheus labels, disruption of worker authentication for other tenants, and a process-wide denial of service.Recommendations
Update Trigger.dev to version 4.5.6.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trigger.Dev