CVE-2026-73654: CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in triggerdotdev trigger.dev
Trigger.dev versions prior to 4.5.6 contain a prototype pollution vulnerability in the PUT /api/v1/runs/:runId/metadata endpoint. This flaw allows an attacker with a normal environment API key to modify Object.prototype in the shared webapp process, leading to corruption of Prisma queries and Prometheus labels, breaking authentication for other tenants, and causing a process-wide denial of service. The vulnerability is fixed in version 4.5.6.
AI Analysis
Technical Summary
Trigger.dev's PUT /api/v1/runs/:runId/metadata endpoint improperly handles attacker-controlled operation.key values by passing them to new JSONHeroPath(operation.key).set(newMetadata, value) without rejecting dangerous constructor and prototype path segments. This allows an attacker to perform prototype pollution on Object.prototype within the shared webapp process. The pollution can corrupt Prisma queries and Prometheus labels, disrupt other tenants' worker authentication, and cause a denial of service affecting the entire process. The vulnerability affects versions prior to 4.5.6 and is fixed in 4.5.6.
Potential Impact
An attacker with a normal environment API key can exploit this vulnerability to modify the Object.prototype, which leads to corruption of database queries and monitoring labels, breaks authentication for other tenants sharing the service, and causes a denial of service that affects the entire process. This results in significant service disruption and potential multi-tenant impact.
Mitigation Recommendations
A fix is available in Trigger.dev version 4.5.6. Users should upgrade to version 4.5.6 or later to remediate this vulnerability. No other mitigation guidance is provided or required.
CVE-2026-73654: CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in triggerdotdev trigger.dev
Description
Trigger.dev versions prior to 4.5.6 contain a prototype pollution vulnerability in the PUT /api/v1/runs/:runId/metadata endpoint. This flaw allows an attacker with a normal environment API key to modify Object.prototype in the shared webapp process, leading to corruption of Prisma queries and Prometheus labels, breaking authentication for other tenants, and causing a process-wide denial of service. The vulnerability is fixed in version 4.5.6.
CVSS v3.1
Score 8.5high
Affected software
triggerdotdev
trigger.dev
pkg:github/triggerdotdev/trigger.devRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Trigger.dev's PUT /api/v1/runs/:runId/metadata endpoint improperly handles attacker-controlled operation.key values by passing them to new JSONHeroPath(operation.key).set(newMetadata, value) without rejecting dangerous constructor and prototype path segments. This allows an attacker to perform prototype pollution on Object.prototype within the shared webapp process. The pollution can corrupt Prisma queries and Prometheus labels, disrupt other tenants' worker authentication, and cause a denial of service affecting the entire process. The vulnerability affects versions prior to 4.5.6 and is fixed in 4.5.6.
Potential Impact
An attacker with a normal environment API key can exploit this vulnerability to modify the Object.prototype, which leads to corruption of database queries and monitoring labels, breaks authentication for other tenants sharing the service, and causes a denial of service that affects the entire process. This results in significant service disruption and potential multi-tenant impact.
Mitigation Recommendations
A fix is available in Trigger.dev version 4.5.6. Users should upgrade to version 4.5.6 or later to remediate this vulnerability. No other mitigation guidance is provided or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-13T14:04:09.604Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7e217cbf8831d539ba0d37
Added to database: 08/13/2026, 19:56:44 UTC
Last enriched: 08/21/2026, 13:53:52 UTC
Last updated: 09/26/2026, 05:46:01 UTC
Views: 61
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.