---
id: GHSA-fj2x-mqqp-3v2w
title: >-
  Trigger.dev: Trigger CLI debug deployment logs expose resolved environment
  secret values
summary: >-
  Trigger.dev: Trigger CLI debug deployment logs expose resolved environment
  secret values
severity: medium
cvss: 5.5
cwe:
  - CWE-532
vendor: trigger.dev
product: trigger.dev
ecosystem: npm
affected:
  - trigger.dev <= 4.5.8
patched:
  - trigger.dev 4.5.9
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T22:45:13Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-fj2x-mqqp-3v2w'
references:
  - url: >-
      https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-fj2x-mqqp-3v2w
  - url: 'https://github.com/triggerdotdev/trigger.dev/pull/4420'
  - url: >-
      https://github.com/triggerdotdev/trigger.dev/commit/878c15811aca8339a751aa0c2211012db7a47ce5
  - url: 'https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.9'
  - url: 'https://github.com/advisories/GHSA-fj2x-mqqp-3v2w'
tags:
  - ghsa
  - npm
ingestedAt: '2026-10-02T23:34:57.399Z'
---

## Overview

Affected version: trigger.dev 4.5.3 (4.5.6 was advertised by the CLI but was not tested).

A staging dry-run executed with `trigger.dev deploy --env staging --dry-run --log-level debug`. The debug output logged the complete build-worker options object. Its `envVars` property contained unredacted values for every resolved staging variable, including database connection strings and service credentials. The non-debug environment listing correctly hides values, so users can reasonably expect deployment logs not to print secrets.

Impact: anyone with access to a developer terminal transcript, CI debug log, captured agent/tool output, or support bundle can recover deployment secrets even though no deployment occurs.

Reproduction:
1. Configure a Trigger.dev project with a secret environment variable.
2. Run the command above with an authenticated profile.
3. Inspect the `Starting buildWorker` debug record.
4. `options.envVars` contains the plaintext value.

No real credential is included in this report. The observed customer credentials are being rotated separately.

Suggested remediation: never serialize `envVars` values in debug output; log names only or replace every value with a fixed marker. Add regression coverage for deploy, dry-run, and debug logging, and review adjacent debug records for resolved secrets.

## Affected packages

- `trigger.dev <= 4.5.8`

## Remediation

Upgrade to a patched release:

- `trigger.dev 4.5.9`
