GHSA-fj2x-mqqp-3v2wMedium· 5.5▾ SunlitTrigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Affected version: trigger.dev 4.5.3 (4.5.6 was advertised by the CLI but was not tested).
A staging dry-run executed with trigger.dev deploy --env staging --dry-run --log-level debug. The debug output logged the complete build-worker options object. Its envVars property contained unredacted values for every resolved staging variable, including database connection strings and service credentials. The non-debug environment listing correctly hides values, so users can reasonably expect deployment logs not to print secrets.
Impact: anyone with access to a developer terminal transcript, CI debug log, captured agent/tool output, or support bundle can recover deployment secrets even though no deployment occurs.
Reproduction:
Starting buildWorker debug record.options.envVars contains the plaintext value.No real credential is included in this report. The observed customer credentials are being rotated separately.
Suggested remediation: never serialize envVars values in debug output; log names only or replace every value with a fixed marker. Add regression coverage for deploy, dry-run, and debug logging, and review adjacent debug records for resolved secrets.
trigger.dev <= 4.5.8Upgrade to a patched release:
trigger.dev 4.5.9Connected by shared product, vendor, weakness, or advisory.
GHSA-q567-cr4x-96w4Medium· 5.4Trigger.dev: Blind SSRF via alert-channel webhook
GHSA-pp95-gc86-jq6qHigh· 7.1Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR)
GHSA-gg6r-gp4c-89hpCriticalTrigger.dev: V1 coordinator default-secret unauth Socket.IO
GHSA-59h8-w5q6-mfmpMedium· 5.3Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId
GHSA-4672-hwv6-gq62Medium· 5.4Trigger.dev: Cross-environment deployment cancel
GHSA-9q4r-4842-93vwHigh· 7.7Trigger.dev: Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function name