GHSA-59h8-w5q6-mfmp: Medium severity npm/trigger.dev vulnerability
Summary
The POST handler for /realtime/v1/streams/:runId/:streamId has no authentication. Any entity that knows or guesses a run friendlyId can inject arbitrary data into its realtime stream.
Vulnerability Details
File: apps/webapp/app/routes/realtime.v1.streams.$runId.$streamId.ts
The action handler (line 17) has no auth wrapper. The code comment says: "Plain action for backwards compatibility with older clients that don't send auth headers."
The run lookup at line 29 uses where: { friendlyId: runId } with NO environment scoping (runtimeEnvironmentId is not checked), so production runs are accessible.
Run friendlyIds follow predictable patterns (e.g., run1234abcd).
Steps to Reproduce
bash No authentication required curl -X POST "http://localhost:8030/realtime/v1/streams/runKNOWNID/stream1" -H "Content-Type: application/json" -d '{"injected": "data"}'
Impact
Unauthenticated data injection into any run realtime stream. Cross-environment access (no scoping).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/trigger.devto a version that resolves this vulnerability.Fixed in 4.5.5
Event History
Frequently Asked Questions
What must an attacker know to target a stream?
No credentials are required. An attacker needs to know or guess a run friendlyId, which follows predictable patterns such as run_1234abcd, and can submit data to the realtime stream endpoint.
Does environment isolation limit exposure to non-production runs?
No. The run lookup does not scope requests to a runtime environment, so production runs can be accessed and data can be injected across environments.