CVE-2026-73654: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the
Summary
Trigger.dev, a platform for building AI agents and workflows, had a security flaw in versions 3.3.8 to 4.5.6 where the PUT /api/v1/runs/:runId/metadata endpoint (a web address for updating run information) accepted attacker-controlled input without proper filtering. This allowed attackers with a normal API key to perform prototype pollution (a type of attack that corrupts shared object properties in JavaScript), which could break database queries, disrupt other users' authentication, and crash the application.
Solution / Mitigation
Update to version 4.5.6 or later.
Vulnerability Details
8.5(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
network
low
low
none
August 13, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73654
First tracked: August 13, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 85%