trigger.dev vulnerabilities
CVEs whose affected-version data names the trigger.dev package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-92773High· 7.1Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization
Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying state cookies and sup…
▾ Twilighttriggerdotdev · trigger.devEPSS 0.31%via NVD
CVE-2026-85651High· 8.5Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments
Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other orga…
▾ Twilighttriggerdotdev · trigger.devEPSS 0.27%via NVD