{"id":"CVE-2026-73657","title":"Trigger.dev is a platform for building and deploying fully managed AI agents and workflows","summary":"Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp/app/routes/api.v1.runs.$runParam.replay.ts uses `prisma.taskRun.…","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-22","CWE-345","CWE-639"],"published":"2026-08-13","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:56:50.520","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73657","references":[{"url":"https://github.com/triggerdotdev/trigger.dev/commit/e1950778e2f2007e2d432b8f8a8fc89531c51f19","label":"security-advisories@github.com"},{"url":"https://github.com/triggerdotdev/trigger.dev/pull/3756","label":"security-advisories@github.com"},{"url":"https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.0-rc.4","label":"security-advisories@github.com"},{"url":"https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-jx48-qfwm-xq67","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.0016,"epssPercentile":0.05584,"ingestedAt":"2026-09-08T21:11:12.277Z","slug":"CVE-2026-73657","body":"## Overview\n\nTrigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp/app/routes/api.v1.runs.$runParam.replay.ts uses `prisma.taskRun.findUnique({ where: { friendlyId: runParam } })` without a runtimeEnvironmentId filter, then ReplayTaskRunService in apps/webapp/app/v3/services/replayTaskRun.server.ts replays the selected run in the victim environment. Any valid environment API key can therefore replay another tenant's run by friendlyId, consuming victim resources and repeating side effects; when `payloadType: \"application/store\"` is used, overrideExistingPayloadPacket() calls conditionallyImportPacket() on existingTaskRun.payload without an integrity check, so payload bytes overwritten through a separate object-store path-traversal vulnerability become attacker-controlled input to the victim task. This issue is fixed in version 4.5.0-rc.4.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}