GHSA-fj2x-mqqp-3v2w: Medium severity npm/trigger.dev vulnerability
Affected version: trigger.dev 4.5.3 (4.5.6 was advertised by the CLI but was not tested).
A staging dry-run executed with trigger.dev deploy --env staging --dry-run --log-level debug. The debug output logged the complete build-worker options object. Its envVars property contained unredacted values for every resolved staging variable, including database connection strings and service credentials. The non-debug environment listing correctly hides values, so users can reasonably expect deployment logs not to print secrets.
Impact: anyone with access to a developer terminal transcript, CI debug log, captured agent/tool output, or support bundle can recover deployment secrets even though no deployment occurs.
Reproduction: 1. Configure a Trigger.dev project with a secret environment variable. 2. Run the command above with an authenticated profile. 3. Inspect the Starting buildWorker debug record. 4. options.envVars contains the plaintext value.
No real credential is included in this report. The observed customer credentials are being rotated separately.
Suggested remediation: never serialize envVars values in debug output; log names only or replace every value with a fixed marker. Add regression coverage for deploy, dry-run, and debug logging, and review adjacent debug records for resolved secrets.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/trigger.devto a version that resolves this vulnerability.Fixed in 4.5.9 - Configuration
Never serialize plaintext envVars values in debug output, including the Starting buildWorker record; emit names only or replace each value with a fixed marker.
Trigger.dev debug logging envVars serialization = log variable names only or replace every value with a fixed marker - Operational
Rotate credentials exposed in the debug output, including database connection strings and service credentials.
- Operational
Add regression coverage for deploy, dry-run, and debug logging, and review adjacent debug records for other resolved secrets.
Event History
Frequently Asked Questions
Who can recover the exposed secrets?
Anyone who can access a developer terminal transcript, CI debug log, captured agent or tool output, or a support bundle containing the debug output can recover the resolved deployment secrets.
What conditions are required to expose environment-variable values?
An authenticated Trigger.dev profile must run a staging dry-run deployment with debug logging enabled: `trigger.dev deploy --env staging --dry-run --log-level debug`. The `Starting buildWorker` debug record then includes plaintext values in `options.envVars`.
Does a deployment need to complete for secrets to be exposed?
No. The reported exposure occurs during a staging dry run, even though no deployment takes place.
How can I determine whether logs contain exposed secrets?
Review debug output from the affected command for the `Starting buildWorker` record. If its `options.envVars` property contains resolved variable values rather than only names or redacted values, the logs contain exposed secrets.