PT-2026-71880 · Unknown · Trigger.Dev

CVE-2026-73659

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Trigger.dev versions 4.4.2 through 4.4.9
Description An issue exists in the packet presign routes located at 'apps/webapp/app/routes/api.v1.packets.$.ts' where a caller-controlled filename is passed through the resolveStoreProtocolForPacketPresign function to generatePresignedUrl and generatePresignedRequest in 'apps/webapp/app/v3/objectStore.server.ts'. This allows for path traversal using .. sequences to escape the 'packets///' object-store prefix. On multi-organization self-hosted instances, an attacker with a project API key can use this to read or overwrite offloaded task payloads and outputs belonging to another organization.
Recommendations Update to version 4.5.0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73659
GHSA-M3MF-37Q7-8928

Affected Products

Trigger.Dev