๐Ÿ” CVE Alert

CVE-2026-73654

HIGH 8.5

Trigger.dev: Prototype pollution via run metadata operations โ†’ process-wide cross-tenant DoS

CVSS Score
8.5
EPSS Score
0.0%
EPSS Percentile
0th

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the PUT /api/v1/runs/:runId/metadata endpoint passes attacker-controlled operation.key values to new JSONHeroPath(operation.key).set(newMetadata, value) in packages/core/src/v3/runMetadata/operations.ts without rejecting dangerous constructor and prototype path segments. A caller with a normal environment API key can pollute Object.prototype in the shared webapp process, corrupting Prisma queries and Prometheus labels, breaking other tenants' worker authentication, and causing a process-wide denial of service. This issue is fixed in version 4.5.6.

CWE CWE-1321
Vendor triggerdotdev
Product trigger.dev
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for triggerdotdev trigger.dev

Be the first to know when new high vulnerabilities affecting triggerdotdev trigger.dev are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
High

Affected Versions

triggerdotdev / trigger.dev
>= 3.3.8, < 4.5.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-p28v-f755-9qrg github.com: https://github.com/triggerdotdev/trigger.dev/pull/4316 github.com: https://github.com/triggerdotdev/trigger.dev/commit/6997aeb05e27d2db47f9eda01fdc8a17c81a1ae0 github.com: https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.6