Background Worker Vulnerability in Trigger.dev Platform
CVE-2026-73656

9.9CRITICAL

Key Information:

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73656?

The Trigger.dev platform, designed for developing and deploying AI agents and workflows, suffers from an improper access control vulnerability. This issue arises from a failure to associate deployments with specific environment IDs, allowing an authenticated user with the right API key to incorrectly access and manipulate deployment identifiers. This could potentially enable an attacker to link their own background worker to an affected deployment, transitioning the deployment from a 'BUILDING' state to 'DEPLOYING', thus disrupting services for the legitimate project owner. A patch has been released in version 4.5.6 to mitigate this vulnerability.

Affected Version(s)

trigger.dev < 4.5.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.