---
id: GHSA-59h8-w5q6-mfmp
title: 'Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId'
summary: 'Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId'
severity: medium
cvss: 5.3
cwe:
  - CWE-306
vendor: trigger.dev
product: trigger.dev
ecosystem: npm
affected:
  - trigger.dev <= 4.5.4
patched:
  - trigger.dev 4.5.5
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T22:39:57Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-59h8-w5q6-mfmp'
references:
  - url: >-
      https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-59h8-w5q6-mfmp
  - url: 'https://github.com/triggerdotdev/trigger.dev/pull/4250'
  - url: >-
      https://github.com/triggerdotdev/trigger.dev/commit/73d966ad226548b5f96fb5b4fc6fa607a3b7b8f8
  - url: 'https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.5'
  - url: 'https://github.com/advisories/GHSA-59h8-w5q6-mfmp'
tags:
  - ghsa
  - npm
ingestedAt: '2026-10-02T23:34:57.403Z'
---

## Overview

## Summary

The POST handler for `/realtime/v1/streams/:runId/:streamId` has no authentication. Any entity that knows or guesses a run friendlyId can inject arbitrary data into its realtime stream.

## Vulnerability Details

**File:** `apps/webapp/app/routes/realtime.v1.streams.$runId.$streamId.ts`

The `action` handler (line 17) has no auth wrapper. The code comment says: "Plain action for backwards compatibility with older clients that don't send auth headers."

The run lookup at line 29 uses `where: { friendlyId: runId }` with NO environment scoping (`runtimeEnvironmentId` is not checked), so production runs are accessible.

Run friendlyIds follow predictable patterns (e.g., `run_1234abcd`).

## Steps to Reproduce

```bash
# No authentication required
curl -X POST "http://localhost:8030/realtime/v1/streams/run_KNOWN_ID/stream_1"   -H "Content-Type: application/json"   -d '{"injected": "data"}'
```

## Impact

Unauthenticated data injection into any run realtime stream. Cross-environment access (no scoping).

## Affected packages

- `trigger.dev <= 4.5.4`

## Remediation

Upgrade to a patched release:

- `trigger.dev 4.5.5`
