PatchSiren

triggerdotdev CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH triggerdotdev CVE published 2026-08-13

CVE-2026-73659

CVE-2026-73659 is a high-severity vulnerability in Trigger.dev, an open-source platform for building AI workflows in TypeScript. The issue, fixed in version 4.5.0, allows unauthorized access to offloaded task payloads and outputs across different organizations on multi-organization self-hosted instances due to a path traversal vulnerability in packet presign routes.

MEDIUM triggerdotdev CVE published 2026-08-13

CVE-2026-73657

CVE-2026-73657 debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T22:17:27.040Z and has not been modified since then. The vulnerability allows unauthorized replay of task runs across tenants in Trigger.dev, potentially leading to resource consumption and side effect repetition. This issue is fixed in version 4.5.0-rc.4. Defenders managing Trigger.dev environments, espe [truncated]