CVE-2026-73654 with a CVSS score of 8.5, affects the @trigger.dev/core package in versions greater than or equal to 3.3.8 and less than or equal to 4.5.5. The flaw is a prototype pollution via run metadata operations, which can lead to process-wide cross-tenant denial-of-service and authentication breakage for other tenants' workers, resulting in query failures and uncaught exceptions. This vulnerability allows an attacker with a normal environment API key to pollute Object.prototype in the shared webapp process, causing full cross-tenant denial of service, contaminated Prisma queries breaking other tenants' worker authentication, and halting job processing. The suggested remediation includes rejecting dangerous path segments in operation.key, building metadata on a null-prototype object, or upgrading/ replacing @jsonhero/path for a version that is prototype-pollution safe.
We recommend you to update @trigger.dev/core to version 4.5.6.[/subscribe_to_unlock_form]
CVE-2026-73654 with a CVSS score of 8.5, affects the @trigger.dev/core package in versions greater than or equal to 3.3.8 and less than or equal to 4.5.5. The flaw is a prototype pollution via run metadata operations, which can lead to process-wide cross-tenant denial-of-service and authentication breakage for other tenants' workers, resulting in query failures and uncaught exceptions. This vulnerability allows an attacker with a normal environment API key to pollute Object.prototype in the shared webapp process, causing full cross-tenant denial of service, contaminated Prisma queries breaking other tenants' worker authentication, and halting job processing. The suggested remediation includes rejecting dangerous path segments in operation.key, building metadata on a null-prototype object, or upgrading/ replacing @jsonhero/path for a version that is prototype-pollution safe.
We recommend you to update @trigger.dev/core to version 4.5.6.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]