Description
Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying state cookies and supplying sequential installation identifiers, gaining unauthorized access to the victim's repositories.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to a victim’s GitHub repositories via GitHub App takeover
Action: Apply Patch
AI Analysis

Impact

Trigger.dev versions prior to 4.6.0 allow an attacker to bind a GitHub App installation to an organization that the attacker does not control. The flaw arises because the application does not verify that the authenticated user actually owns or is authorized for the GitHub App installation before binding it. Once bound, the attacker gains the permissions granted to that installation, enabling them to read, modify, or delete the victim’s repositories and related data. This represents a significant confidentiality and integrity breach but does not provide arbitrary code execution on the host system.

Affected Systems

The vulnerability exists in all releases of trigger.dev earlier than 4.6.0. The vendor product is triggerdotdev:trigger.dev. No specific subcomponent version numbers beyond the major release are listed; the fix begins with release 4.6.0.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity flaw. The EPSS score is reported as less than 1%, suggesting that the likelihood of exploitation is low at present. The vulnerability is not listed in the CISA KEV catalog, and no public exploits have been confirmed. The likely attack vector is via the web application, requiring the attacker to replay a state cookie from a victim and supply a sequential installation identifier. This implies the attacker must obtain a valid state cookie, which could be achieved through social engineering or credential compromise. If successful, the attacker can take over the targeted GitHub App and access the victim’s repositories.

Generated by OpenCVE AI on September 18, 2026 at 06:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade trigger.dev to version 4.6.0 or later, which implements ownership verification for GitHub App installations
  • Implement an additional check in the deployment pipeline to ensure that only verified GitHub App installations can be provisioned to an organization
  • Vet any GitHub App installation requests and audit the list of installed apps to detect unauthorized takeovers

Generated by OpenCVE AI on September 18, 2026 at 06:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Triggerdotdev
Triggerdotdev trigger.dev
Vendors & Products Triggerdotdev
Triggerdotdev trigger.dev

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying state cookies and supplying sequential installation identifiers, gaining unauthorized access to the victim's repositories.
Title Trigger.dev before 4.6.0 GitHub App Installation Takeover
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

Triggerdotdev Trigger.dev
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:25:13.643Z

Reserved: 2026-09-16T19:15:39.366Z

Link: CVE-2026-92773

cve-icon Vulnrichment

Updated: 2026-09-17T19:16:55.379Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:26.063

Modified: 2026-09-23T17:17:48.290

Link: CVE-2026-92773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:30:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key