PT-2026-85551 · Unknown · Trigger.Dev

·

CVE-2026-85650

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Trigger.dev versions prior to 4.5.2
Description Authenticated users with organization membership can exploit a server-side request forgery (SSRF) issue. This occurs because webhook alert channel delivery URLs are fetched without proper validation or protection. An attacker can create alert channels with URLs targeting internal services and metadata endpoints, causing the server to issue POST requests to restricted resources.
Recommendations Update to version 4.5.2 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85650
GHSA-XXV7-2VV3-H682

Affected Products

Trigger.Dev