{"id":"GHSA-fj2x-mqqp-3v2w","title":"Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values","summary":"Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values","severity":"medium","cvss":5.5,"cwe":["CWE-532"],"vendor":"trigger.dev","product":"trigger.dev","ecosystem":"npm","affected":["trigger.dev <= 4.5.8"],"patched":["trigger.dev 4.5.9"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T22:45:13Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-fj2x-mqqp-3v2w","references":[{"url":"https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-fj2x-mqqp-3v2w"},{"url":"https://github.com/triggerdotdev/trigger.dev/pull/4420"},{"url":"https://github.com/triggerdotdev/trigger.dev/commit/878c15811aca8339a751aa0c2211012db7a47ce5"},{"url":"https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.9"},{"url":"https://github.com/advisories/GHSA-fj2x-mqqp-3v2w"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-02T23:34:57.399Z","slug":"GHSA-fj2x-mqqp-3v2w","body":"## Overview\n\nAffected version: trigger.dev 4.5.3 (4.5.6 was advertised by the CLI but was not tested).\n\nA staging dry-run executed with `trigger.dev deploy --env staging --dry-run --log-level debug`. The debug output logged the complete build-worker options object. Its `envVars` property contained unredacted values for every resolved staging variable, including database connection strings and service credentials. The non-debug environment listing correctly hides values, so users can reasonably expect deployment logs not to print secrets.\n\nImpact: anyone with access to a developer terminal transcript, CI debug log, captured agent/tool output, or support bundle can recover deployment secrets even though no deployment occurs.\n\nReproduction:\n1. Configure a Trigger.dev project with a secret environment variable.\n2. Run the command above with an authenticated profile.\n3. Inspect the `Starting buildWorker` debug record.\n4. `options.envVars` contains the plaintext value.\n\nNo real credential is included in this report. The observed customer credentials are being rotated separately.\n\nSuggested remediation: never serialize `envVars` values in debug output; log names only or replace every value with a fixed marker. Add regression coverage for deploy, dry-run, and debug logging, and review adjacent debug records for resolved secrets.\n\n## Affected packages\n\n- `trigger.dev <= 4.5.8`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `trigger.dev 4.5.9`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}