Background Worker Vulnerability in Trigger.dev Platform
CVE-2026-73656
9.9CRITICAL
What is CVE-2026-73656?
The Trigger.dev platform, designed for developing and deploying AI agents and workflows, suffers from an improper access control vulnerability. This issue arises from a failure to associate deployments with specific environment IDs, allowing an authenticated user with the right API key to incorrectly access and manipulate deployment identifiers. This could potentially enable an attacker to link their own background worker to an affected deployment, transitioning the deployment from a 'BUILDING' state to 'DEPLOYING', thus disrupting services for the legitimate project owner. A patch has been released in version 4.5.6 to mitigate this vulnerability.
Affected Version(s)
trigger.dev < 4.5.2
