Cross-Site Scripting Vulnerability in Trigger.dev's Object Store Client
CVE-2026-73658

8.2HIGH

Key Information:

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73658?

Trigger.dev, a platform for managing AI workflows, has a vulnerability that affects versions 4.4.2 through 4.5.0-rc.5. Specifically, the Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() methods allow user-controlled packet keys to manipulate the URL pathname. Additionally, the API routes do not adequately validate input parameters, potentially enabling unauthorized users to access or modify resources that should be protected. Exploiting this flaw, an attacker with a valid environment API key can acquire presigned URLs for another tenant's object-store keys, leading to unauthorized read or overwrite access of task payloads. The issue has been addressed in the release of version 4.5.0-rc.5.

Affected Version(s)

trigger.dev >= 4.4.2, < 4.5.0-rc.5

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.