GitHub App Installation Vulnerability in Trigger.dev by Trigger.dev
CVE-2026-92773

7.1HIGH

Key Information:

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92773?

The vulnerability in Trigger.dev allows authenticated users to exploit a flaw in the GitHub App installation verification process. Prior to version 4.6.0, Trigger.dev did not adequately ensure that users controlled their GitHub App installations, making it possible for an attacker to take over another user's GitHub App installation. This could be achieved by replaying state cookies and providing sequential installation identifiers, enabling unauthorized access to the victim's repositories and sensitive data.

Affected Version(s)

trigger.dev 0 < 4.6.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.