PatchSiren cyber security CVE debrief
CVE-2026-73657 triggerdotdev CVE debrief
CVE-2026-73657 debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T22:17:27.040Z and has not been modified since then. The vulnerability allows unauthorized replay of task runs across tenants in Trigger.dev, potentially leading to resource consumption and side effect repetition. This issue is fixed in version 4.5.0-rc.4. Defenders managing Trigger.dev environments, especially those with multiple tenants and untrusted users, should assess exposure and prioritize updating to the fixed version.
- Vendor
- triggerdotdev
- Product
- trigger.dev
- CVSS
- MEDIUM 4.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-09-08
Who should care
Defenders managing Trigger.dev environments, especially those with multiple tenants and untrusted users, should assess exposure and prioritize updating to the fixed version. Defenders should prioritize verifying exposure in Trigger.dev environments, especially those with multiple tenants and untrusted users.
Why it matters
CVE-2026-73657 allows unauthorized replay of task runs across tenants in Trigger.dev, potentially leading to resource consumption and side effect repetition.
- Potential unauthorized consumption of victim resources.
- Possible repetition of side effects in victim environments.
- Potential for payload tampering through separate object-store path-traversal vulnerabilities.
Technical summary
The Trigger.dev platform had a vulnerability allowing unauthorized replay of task runs across tenants due to insufficient filtering in the replay API endpoint. This vulnerability allows unauthorized replay of task runs across tenants in Trigger.dev, potentially leading to resource consumption and side effect repetition. The issue is fixed in version 4.5.0-rc.4. Defenders should prioritize verifying exposure in Trigger.dev environments, especially those with multiple tenants and untrusted users. The vulnerability allows unauthorized replay of task runs across tenants in Trigger.dev, potentially leading to resource consumption and side effect repetition.
Defensive priority
Defenders should prioritize verifying exposure in Trigger.dev environments, especially those with multiple tenants and untrusted users.
Recommended defensive actions
- Verify Trigger.dev environments for exposure, especially those with multiple tenants and untrusted users.
- Update to version 4.5.0-rc.4 or later.
- Monitor for suspicious task run activity.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
Evidence from Trigger.dev and GitHub indicates a vulnerability in Trigger.dev versions 4.4.2 to 4.5.0-rc.4 allowing unauthorized replay of task runs across tenants. The vulnerability allows unauthorized replay of task runs across tenants in Trigger.dev, potentially leading to resource consumption and side effect repetition. This issue is fixed in version 4.5.0-rc.4.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73657 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73657
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73657 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73657
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/triggerdotdev/trigger.dev/commit/e1950778e2f2007e2d432b8f8a8fc89531c51f19
-
Source reference
Unverified legacy reference
URL: https://github.com/triggerdotdev/trigger.dev/pull/3756
-
Source reference
Unverified legacy reference
URL: https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.0-rc.4
-
Source reference
Unverified legacy reference
URL: https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-jx48-qfwm-xq67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.