---
id: CVE-2026-92773
title: >-
  Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a
  GitHub App installation before binding it to their organization
summary: >-
  Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a
  GitHub App installation before binding it to their organization. Attackers can
  claim another user's GitHub App installation by replaying state cookies and
  sup…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N'
cwe:
  - CWE-639
vendor: triggerdotdev
product: trigger.dev
affected:
  - trigger.dev < 4.6.0
published: '2026-09-16'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:48.290'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92773'
references:
  - url: 'https://github.com/triggerdotdev/trigger.dev'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/triggerdotdev/trigger.dev/blob/v4.5.16/apps/webapp/app/services/gitHub.server.ts
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/triggerdotdev/trigger.dev/blob/v4.6.0/apps/webapp/app/services/gitHub.server.ts#L83-L86
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-9rx3-j5hm-5f27
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/trigger-dev-before-4.6.0-github-app-installation-takeover
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00323
epssPercentile: 0.22671
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T19:16:54.308008Z'
ingestedAt: '2026-09-16T21:05:36.893Z'
---

## Overview

Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying state cookies and supplying sequential installation identifiers, gaining unauthorized access to the victim's repositories.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
