PT-2026-71833 · Unknown · Trigger.Dev

CVE-2026-73656

·

Published

2026-08-13

·

Updated

2026-08-14

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trigger.dev versions prior to 4.5.6
Description An issue exists in the platform for building and deploying managed AI agents and workflows. The endpoint "/api/v1/deployments/:deploymentId/background-workers" invokes the CreateDeploymentBackgroundWorkerServiceV4.call() function, where the workerDeployment.findFirst() method selects a deployment using a friendlyId without verifying the environmentId. This allows a user with a valid API key for one project to provide a deployment identifier from another project, linking an attacker-controlled background worker to the victim deployment and changing its status from BUILDING to DEPLOYING.
Recommendations Update to version 4.5.6.

Exploit

Fix

Missing Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73656
GHSA-J6VV-PQ9H-F4WJ

Affected Products

Trigger.Dev