{"data":{"id":"79280d10-b017-499f-8369-6a6aac386d19","title":"CVE-2026-73654: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the ","summary":"Trigger.dev, a platform for building AI agents and workflows, had a security flaw in versions 3.3.8 to 4.5.6 where the PUT /api/v1/runs/:runId/metadata endpoint (a web address for updating run information) accepted attacker-controlled input without proper filtering. This allowed attackers with a normal API key to perform prototype pollution (a type of attack that corrupts shared object properties in JavaScript), which could break database queries, disrupt other users' authentication, and crash the application.","solution":"Update to version 4.5.6 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73654","publishedAt":"2026-08-13T20:17:30.007Z","cveId":"CVE-2026-73654","cweIds":["CWE-1321"],"cvssScore":"8.5","cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["Trigger.dev"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-13T20:17:30.007Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability","confidentiality"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]}}