CVE-2026-73658: CWE-20: Improper Input Validation in triggerdotdev trigger.dev
CVE-2026-73658 is a high-severity vulnerability in trigger.dev, a platform for building and deploying AI agents and workflows. Versions from 4.4.2 up to but not including 4.5.0-rc.5 contain improper input validation in the Aws4FetchClient component, allowing user-controlled packet keys to be assigned to URL pathnames without proper normalization and ownership checks. This flaw enables an attacker with a valid environment API key to obtain presigned URLs for other tenants' object-store keys, potentially reading or overwriting task payloads. The issue is fixed starting from version 4.5.0-rc.5. The vulnerability has a CVSS score of 8.2, indicating high impact on confidentiality and integrity but no impact on availability.
AI Analysis
Technical Summary
Trigger.dev versions from 4.4.2 until 4.5.0-rc.5 have an improper input validation vulnerability (CWE-20) combined with path traversal issues (CWE-22) and missing authorization checks (CWE-862) in the Aws4FetchClient component. Specifically, user-controlled packet keys are assigned to URL.pathname without rejecting dot segments, and path normalization collapses '..' segments before signing. The API accepts parameters without rejecting these segments and uses a resource finder that does not validate resource ownership. This allows an attacker with a valid environment API key to generate presigned URLs for object-store keys belonging to other tenants, enabling unauthorized read or overwrite of task payloads. The vulnerability is fixed in version 4.5.0-rc.5. The CVSS 3.1 vector is AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N, reflecting network attack vector, high attack complexity, low privileges required, no user interaction, scope change, high confidentiality and integrity impact, and no availability impact.
Potential Impact
An attacker with a valid environment API key can exploit this vulnerability to obtain presigned URLs for object-store keys of other tenants, allowing unauthorized reading or overwriting of task payloads. This compromises confidentiality and integrity of data across tenant boundaries within the trigger.dev platform. There is no impact on availability. The vulnerability affects multi-tenant isolation and access control mechanisms.
Mitigation Recommendations
The vendor manages remediation for this cloud-hosted service. The issue is fixed in trigger.dev version 4.5.0-rc.5. Users should ensure they are using version 4.5.0-rc.5 or later to mitigate this vulnerability. Patch status is confirmed as fixed starting from 4.5.0-rc.5. No additional mitigation steps are indicated by the vendor advisory.
CVE-2026-73658: CWE-20: Improper Input Validation in triggerdotdev trigger.dev
Description
CVE-2026-73658 is a high-severity vulnerability in trigger.dev, a platform for building and deploying AI agents and workflows. Versions from 4.4.2 up to but not including 4.5.0-rc.5 contain improper input validation in the Aws4FetchClient component, allowing user-controlled packet keys to be assigned to URL pathnames without proper normalization and ownership checks. This flaw enables an attacker with a valid environment API key to obtain presigned URLs for other tenants' object-store keys, potentially reading or overwriting task payloads. The issue is fixed starting from version 4.5.0-rc.5. The vulnerability has a CVSS score of 8.2, indicating high impact on confidentiality and integrity but no impact on availability.
CVSS v3.1
Score 8.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Trigger.dev versions from 4.4.2 until 4.5.0-rc.5 have an improper input validation vulnerability (CWE-20) combined with path traversal issues (CWE-22) and missing authorization checks (CWE-862) in the Aws4FetchClient component. Specifically, user-controlled packet keys are assigned to URL.pathname without rejecting dot segments, and path normalization collapses '..' segments before signing. The API accepts parameters without rejecting these segments and uses a resource finder that does not validate resource ownership. This allows an attacker with a valid environment API key to generate presigned URLs for object-store keys belonging to other tenants, enabling unauthorized read or overwrite of task payloads. The vulnerability is fixed in version 4.5.0-rc.5. The CVSS 3.1 vector is AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N, reflecting network attack vector, high attack complexity, low privileges required, no user interaction, scope change, high confidentiality and integrity impact, and no availability impact.
Potential Impact
An attacker with a valid environment API key can exploit this vulnerability to obtain presigned URLs for object-store keys of other tenants, allowing unauthorized reading or overwriting of task payloads. This compromises confidentiality and integrity of data across tenant boundaries within the trigger.dev platform. There is no impact on availability. The vulnerability affects multi-tenant isolation and access control mechanisms.
Mitigation Recommendations
The vendor manages remediation for this cloud-hosted service. The issue is fixed in trigger.dev version 4.5.0-rc.5. Users should ensure they are using version 4.5.0-rc.5 or later to mitigate this vulnerability. Patch status is confirmed as fixed starting from 4.5.0-rc.5. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-13T14:04:09.605Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Is Cloud Service
- true
Threat ID: 6a7e3a17bf8831d539d7043f
Added to database: 08/13/2026, 21:41:43 UTC
Last enriched: 08/13/2026, 21:56:41 UTC
Last updated: 08/13/2026, 22:01:14 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.