CVE-2026-85650: Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel
Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert channels with URLs targeting internal services and metadata endpoints, allowing the server to issue POST requests to restricted resources.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Trigger.devto a version that resolves this vulnerability.Fixed in 4.5.2 - Compensating control
Restrict or disable webhook alert-channel URL delivery for authenticated users (organization members) until Trigger.dev is upgraded to 4.5.2, to prevent POST requests to internal services and metadata endpoints.
Event History
Frequently Asked Questions
Who needs access to exploit this issue?
An authenticated user with membership in an organization can create an alert channel with a chosen delivery URL. Exploitation does not require user interaction and is rated low complexity.
Which deployments are affected?
Trigger.dev versions before 4.5.2 are affected. Deployments running version 4.5.2 or later are not identified as affected by the provided data.
What can a successful exploit cause?
The Trigger.dev server can be induced to send POST requests to internal services or metadata endpoints that would otherwise be restricted. The reported impact is low confidentiality and low integrity impact, with no availability impact.