Multiple vulnerabilities in Trigger.dev platform
Five CVEs affecting Trigger.dev versions 3.3.8 through 4.5.6 allow prototype pollution, account takeover, cross-tenant resource access, and payload manipulation via insufficient input validation and missing ownership checks.
Disclosed 13 August 2026 · Record updated 13 September 2026
Impact
Prototype pollution causing denial of service and tenant isolation bypass, account takeover via unverified email, cross-tenant deployment and run manipulation, and payload tampering across multiple vulnerabilities.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73654
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73655
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73656
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73657
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73658
