Threat Advisory

Trigger.dev Prototype Pollution via Run Metadata Operations

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-73654 with a CVSS score of 8.5, affects the @trigger.dev/core package in versions greater than or equal to 3.3.8 and less than or equal to 4.5.5. The flaw is a prototype pollution via run metadata operations, which can lead to process-wide cross-tenant denial-of-service and authentication breakage for other tenants' workers, resulting in query failures and uncaught exceptions. This vulnerability allows an attacker with a normal environment API key to pollute Object.prototype in the shared webapp process, causing full cross-tenant denial of service, contaminated Prisma queries breaking other tenants' worker authentication, and halting job processing. The suggested remediation includes rejecting dangerous path segments in operation.key, building metadata on a null-prototype object, or upgrading/ replacing @jsonhero/path for a version that is prototype-pollution safe.

RECOMMENDATION:

We recommend you to update @trigger.dev/core to version 4.5.6.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-73654 with a CVSS score of 8.5, affects the @trigger.dev/core package in versions greater than or equal to 3.3.8 and less than or equal to 4.5.5. The flaw is a prototype pollution via run metadata operations, which can lead to process-wide cross-tenant denial-of-service and authentication breakage for other tenants' workers, resulting in query failures and uncaught exceptions. This vulnerability allows an attacker with a normal environment API key to pollute Object.prototype in the shared webapp process, causing full cross-tenant denial of service, contaminated Prisma queries breaking other tenants' worker authentication, and halting job processing. The suggested remediation includes rejecting dangerous path segments in operation.key, building metadata on a null-prototype object, or upgrading/ replacing @jsonhero/path for a version that is prototype-pollution safe.

RECOMMENDATION:

We recommend you to update @trigger.dev/core to version 4.5.6.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu