CVE-2026-85651EPSS p39.6%

CVE-2026-85651CVE-2026-85651

Description

Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to consume victim resources and pollute run history.

Scoring

CVSS 8.5 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
EPSS0.49% probability of exploitation · percentile 39.6% · 2026-10-05T12:00:23Z
Last modified2026-09-23
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.