Cross-Site Scripting Vulnerability in Trigger.dev's Object Store Client
CVE-2026-73658
8.2HIGH
What is CVE-2026-73658?
Trigger.dev, a platform for managing AI workflows, has a vulnerability that affects versions 4.4.2 through 4.5.0-rc.5. Specifically, the Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() methods allow user-controlled packet keys to manipulate the URL pathname. Additionally, the API routes do not adequately validate input parameters, potentially enabling unauthorized users to access or modify resources that should be protected. Exploiting this flaw, an attacker with a valid environment API key can acquire presigned URLs for another tenant's object-store keys, leading to unauthorized read or overwrite access of task payloads. The issue has been addressed in the release of version 4.5.0-rc.5.
Affected Version(s)
trigger.dev >= 4.4.2, < 4.5.0-rc.5
