GHSA-59h8-w5q6-mfmpMediumCVSS 5.3Disclosed before NVD
Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId
📋 Description
Summary
The POST handler for /realtime/v1/streams/:runId/:streamId has no authentication. Any entity that knows or guesses a run friendlyId can inject arbitrary data into its realtime stream.
Vulnerability Details
File: apps/webapp/app/routes/realtime.v1.streams.$runId.$streamId.ts
The action handler (line 17) has no auth wrapper. The code comment says: "Plain action for backwards compatibility with older clients that don't send auth headers."
The run lookup at line 29 uses where: { friendlyId: runId } with NO environment scoping (runtimeEnvironmentId is not checked), so production runs are accessible.
Run friendlyIds follow predictable patterns (e.g., run_1234abcd).
Steps to Reproduce
# No authentication required
curl -X POST "http://localhost:8030/realtime/v1/streams/run_KNOWN_ID/stream_1" -H "Content-Type: application/json" -d '{"injected": "data"}'
Impact
Unauthenticated data injection into any run realtime stream. Cross-environment access (no scoping).
🎯 Affected products1
- npm/trigger.dev:<= 4.5.4
🔗 References (5)
- https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-59h8-w5q6-mfmp
- https://github.com/triggerdotdev/trigger.dev/pull/4250
- https://github.com/triggerdotdev/trigger.dev/commit/73d966ad226548b5f96fb5b4fc6fa607a3b7b8f8
- https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.5
- https://github.com/advisories/GHSA-59h8-w5q6-mfmp