Impact
Trigger.dev’s object‑store client constructed URLs with user‑controlled packet keys and omitted proper path‑segment sanitization. The corresponding API route accepted wildcard path parameters and performed no per‑resource ownership validation. Path normalization collapsed ". ." segments before signing, enabling an attacker with a valid environment API key to generate presigned URLs that reference another tenant’s object‑store keys. The result is the ability to read or overwrite another tenant’s payloads, compromising confidentiality and integrity in a multi‑tenant deployment. The likely attack vector, inferred from the description, is a legitimate API‑key holder crafting malicious URLs through standard API calls.
Affected Systems
Trigger.dev, versions 4.4.2 through 4.5.0‑rc.5, are affected. All deployments that use the impacted object‑store client and API route during this version range are at risk, regardless of tenant configuration.
Risk and Exploitability
The CVSS score of 8.2 reflects high severity, and no EPSS score is currently available. The vulnerability is not listed in the CISA KEV catalog. Attackers require only a valid environment API key and can otherwise use normal API calls to obtain presigned URLs for resources owned by other tenants. The flaw is exploitable without elevated privileges, presenting a substantial risk for any organization relying on tenant isolation.
OpenCVE Enrichment