GHSA-59h8-w5q6-mfmp

Suggest an improvement
Source
https://github.com/advisories/GHSA-59h8-w5q6-mfmp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-59h8-w5q6-mfmp/GHSA-59h8-w5q6-mfmp.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-59h8-w5q6-mfmp
Downstream
Published
2026-10-02T22:39:57Z
Modified
2026-10-02T23:00:20Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId
Details

Summary

The POST handler for /realtime/v1/streams/:runId/:streamId has no authentication. Any entity that knows or guesses a run friendlyId can inject arbitrary data into its realtime stream.

Vulnerability Details

File: apps/webapp/app/routes/realtime.v1.streams.$runId.$streamId.ts

The action handler (line 17) has no auth wrapper. The code comment says: "Plain action for backwards compatibility with older clients that don't send auth headers."

The run lookup at line 29 uses where: { friendlyId: runId } with NO environment scoping (runtimeEnvironmentId is not checked), so production runs are accessible.

Run friendlyIds follow predictable patterns (e.g., run_1234abcd).

Steps to Reproduce

# No authentication required
curl -X POST "http://localhost:8030/realtime/v1/streams/run_KNOWN_ID/stream_1"   -H "Content-Type: application/json"   -d '{"injected": "data"}'

Impact

Unauthenticated data injection into any run realtime stream. Cross-environment access (no scoping).

Database specific
{
    "cwe_ids": [
        "CWE-306"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-02T22:39:57Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

npm / trigger.dev

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.5.5

Database specific

last_known_affected_version_range
"<= 4.5.4"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-59h8-w5q6-mfmp/GHSA-59h8-w5q6-mfmp.json"