Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/v3/services/createDeploymentBackgroundWorkerV4.server.ts, where workerDeployment.findFirst() selects a deployment by friendlyId without an environmentId predicate. A caller with a valid API key for one project can submit another project's deployment identifier, link an attacker-owned background worker to the victim deployment, and move the victim deployment from BUILDING to DEPLOYING. This issue is fixed in version 4.5.6.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-13 20:17
Updated : 2026-08-14 19:18
NVD link : CVE-2026-73656
Mitre link : CVE-2026-73656
CVE.ORG link : CVE-2026-73656
JSON object : View
Products Affected
No product.
