{"id":"GHSA-59h8-w5q6-mfmp","title":"Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId","summary":"Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId","severity":"medium","cvss":5.3,"cwe":["CWE-306"],"vendor":"trigger.dev","product":"trigger.dev","ecosystem":"npm","affected":["trigger.dev <= 4.5.4"],"patched":["trigger.dev 4.5.5"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T22:39:57Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-59h8-w5q6-mfmp","references":[{"url":"https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-59h8-w5q6-mfmp"},{"url":"https://github.com/triggerdotdev/trigger.dev/pull/4250"},{"url":"https://github.com/triggerdotdev/trigger.dev/commit/73d966ad226548b5f96fb5b4fc6fa607a3b7b8f8"},{"url":"https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.5"},{"url":"https://github.com/advisories/GHSA-59h8-w5q6-mfmp"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-02T23:34:57.403Z","slug":"GHSA-59h8-w5q6-mfmp","body":"## Overview\n\n## Summary\n\nThe POST handler for `/realtime/v1/streams/:runId/:streamId` has no authentication. Any entity that knows or guesses a run friendlyId can inject arbitrary data into its realtime stream.\n\n## Vulnerability Details\n\n**File:** `apps/webapp/app/routes/realtime.v1.streams.$runId.$streamId.ts`\n\nThe `action` handler (line 17) has no auth wrapper. The code comment says: \"Plain action for backwards compatibility with older clients that don't send auth headers.\"\n\nThe run lookup at line 29 uses `where: { friendlyId: runId }` with NO environment scoping (`runtimeEnvironmentId` is not checked), so production runs are accessible.\n\nRun friendlyIds follow predictable patterns (e.g., `run_1234abcd`).\n\n## Steps to Reproduce\n\n```bash\n# No authentication required\ncurl -X POST \"http://localhost:8030/realtime/v1/streams/run_KNOWN_ID/stream_1\"   -H \"Content-Type: application/json\"   -d '{\"injected\": \"data\"}'\n```\n\n## Impact\n\nUnauthenticated data injection into any run realtime stream. Cross-environment access (no scoping).\n\n## Affected packages\n\n- `trigger.dev <= 4.5.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `trigger.dev 4.5.5`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}