GHSA-fj2x-mqqp-3v2w: Medium severity npm/trigger.dev vulnerability

Published Oct 2, 2026
·
Updated

Affected version: trigger.dev 4.5.3 (4.5.6 was advertised by the CLI but was not tested).

A staging dry-run executed with trigger.dev deploy --env staging --dry-run --log-level debug. The debug output logged the complete build-worker options object. Its envVars property contained unredacted values for every resolved staging variable, including database connection strings and service credentials. The non-debug environment listing correctly hides values, so users can reasonably expect deployment logs not to print secrets.

Impact: anyone with access to a developer terminal transcript, CI debug log, captured agent/tool output, or support bundle can recover deployment secrets even though no deployment occurs.

Reproduction: 1. Configure a Trigger.dev project with a secret environment variable. 2. Run the command above with an authenticated profile. 3. Inspect the Starting buildWorker debug record. 4. options.envVars contains the plaintext value.

No real credential is included in this report. The observed customer credentials are being rotated separately.

Suggested remediation: never serialize envVars values in debug output; log names only or replace every value with a fixed marker. Add regression coverage for deploy, dry-run, and debug logging, and review adjacent debug records for resolved secrets.

Affected Software

1 affected componentFixes available
npm/trigger.dev<=4.5.8
4.5.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/trigger.dev to a version that resolves this vulnerability.

    Fixed in 4.5.9
  2. Configuration

    Never serialize plaintext envVars values in debug output, including the Starting buildWorker record; emit names only or replace each value with a fixed marker.

    Trigger.dev debug logging envVars serialization = log variable names only or replace every value with a fixed marker
  3. Operational

    Rotate credentials exposed in the debug output, including database connection strings and service credentials.

  4. Operational

    Add regression coverage for deploy, dry-run, and debug logging, and review adjacent debug records for other resolved secrets.

Event History

Oct 2, 2026
Advisory Published
via GitHub·10:45 PM
Data Sourced
via GitHub·10:45 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can recover the exposed secrets?

Anyone who can access a developer terminal transcript, CI debug log, captured agent or tool output, or a support bundle containing the debug output can recover the resolved deployment secrets.

2

What conditions are required to expose environment-variable values?

An authenticated Trigger.dev profile must run a staging dry-run deployment with debug logging enabled: `trigger.dev deploy --env staging --dry-run --log-level debug`. The `Starting buildWorker` debug record then includes plaintext values in `options.envVars`.

3

Does a deployment need to complete for secrets to be exposed?

No. The reported exposure occurs during a staging dry run, even though no deployment takes place.

4

How can I determine whether logs contain exposed secrets?

Review debug output from the affected command for the `Starting buildWorker` record. If its `options.envVars` property contains resolved variable values rather than only names or redacted values, the logs contain exposed secrets.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203