CVE-2026-73655: CWE-287: Improper Authentication in triggerdotdev trigger.dev
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() in apps/webapp/app/models/user.server.ts without requiring Google's email_verified assertion. When existingEmailUser && !existingUser is true, the flow writes the new Google authIdentifier into the existing email-matched account and returns that user object, allowing an attacker-controlled Google profile with an unverified matching email to take over the account. This issue is fixed in version 4.5.2.
AI Analysis
Technical Summary
Trigger.dev's addGoogleStrategy() function in versions before 4.5.2 passes a Google profile email to findOrCreateGoogleUser() without verifying the email_verified assertion from Google. When an existing user account matches the email but lacks the Google auth identifier, the system writes the attacker-controlled Google auth identifier into the existing account, enabling account takeover. This improper authentication vulnerability is tracked as CVE-2026-73655 and is fixed in version 4.5.2.
Potential Impact
An attacker can take over user accounts by exploiting the lack of verification of Google's email_verified assertion, leading to unauthorized access and potential compromise of user data. The vulnerability impacts confidentiality and integrity but does not affect availability.
Mitigation Recommendations
Upgrade to trigger.dev version 4.5.2 or later, where the issue is fixed by properly requiring Google's email_verified assertion before associating Google authentication identifiers with user accounts.
CVE-2026-73655: CWE-287: Improper Authentication in triggerdotdev trigger.dev
Description
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() in apps/webapp/app/models/user.server.ts without requiring Google's email_verified assertion. When existingEmailUser && !existingUser is true, the flow writes the new Google authIdentifier into the existing email-matched account and returns that user object, allowing an attacker-controlled Google profile with an unverified matching email to take over the account. This issue is fixed in version 4.5.2.
CVSS v3.1
Score 7.4high
Affected software
triggerdotdev
trigger.dev
pkg:github/triggerdotdev/trigger.devRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Trigger.dev's addGoogleStrategy() function in versions before 4.5.2 passes a Google profile email to findOrCreateGoogleUser() without verifying the email_verified assertion from Google. When an existing user account matches the email but lacks the Google auth identifier, the system writes the attacker-controlled Google auth identifier into the existing account, enabling account takeover. This improper authentication vulnerability is tracked as CVE-2026-73655 and is fixed in version 4.5.2.
Potential Impact
An attacker can take over user accounts by exploiting the lack of verification of Google's email_verified assertion, leading to unauthorized access and potential compromise of user data. The vulnerability impacts confidentiality and integrity but does not affect availability.
Mitigation Recommendations
Upgrade to trigger.dev version 4.5.2 or later, where the issue is fixed by properly requiring Google's email_verified assertion before associating Google authentication identifiers with user accounts.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-13T14:04:09.605Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7e2504bf8831d539bed84a
Added to database: 08/13/2026, 20:11:48 UTC
Last enriched: 08/21/2026, 13:06:16 UTC
Last updated: 09/27/2026, 13:47:47 UTC
Views: 83
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.