---
id: CVE-2026-85651
title: >-
  Trigger.dev versions before 4.5.2 fail to validate environment membership
  during run replay operations, allowing authenticated attackers to inject task
  runs into arbitrary environments
summary: >-
  Trigger.dev versions before 4.5.2 fail to validate environment membership
  during run replay operations, allowing authenticated attackers to inject task
  runs into arbitrary environments. Attackers can replay their own runs into
  other orga…
severity: high
cvss: 8.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L'
cwe:
  - CWE-862
vendor: triggerdotdev
product: trigger.dev
affected:
  - trigger.dev < 4.5.2
published: '2026-09-04'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:43.317'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85651'
references:
  - url: 'https://github.com/triggerdotdev/trigger.dev'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/triggerdotdev/trigger.dev/commit/34b1a181c2a1d33a53ebab88f84b05f81fea4254
    label: disclosure@vulncheck.com
  - url: 'https://github.com/triggerdotdev/trigger.dev/issues/4173'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.2'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-qxpp-qjg8-x4jv
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/trigger-dev-before-4.5.2-unauthorized-environment-access-via-run-replay
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00486
epssPercentile: 0.39136
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T14:19:17.898529Z'
ingestedAt: '2026-09-10T15:53:17.107Z'
---

## Overview

Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to consume victim resources and pollute run history.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
