trigger.dev
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting trigger.devpage 1 of 1
- CVE-2026-85650MEDIUMCVSS 5.4EG 5.4fixed in 4.5.22026-09-04
Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert …
- CVE-2026-85651HIGHCVSS 8.5EG 8.5fixed in 4.5.22026-09-04
Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organi…
Check whether trigger.dev is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for trigger.dev CVEs against the assets you own.
Book a Demo →