CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1
Summary
Trigger.dev, a platform for building AI agents and workflows, had a security flaw in versions before 4.5.6 where an API endpoint didn't properly check which project owned a deployment. This allowed someone with a valid API key for one project to hijack another project's deployment by attaching their own background worker (a component that runs tasks in the background) to it and changing its status.
Solution / Mitigation
This issue is fixed in version 4.5.6.
Vulnerability Details
9.9(critical)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
network
low
low
none
August 13, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73656
First tracked: August 13, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 85%