CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-FJ2X-MQQP-3V2W

GHSA-FJ2X-MQQP-3V2W: Sensitive Information Disclosure in Trigger.dev CLI Build Logs

Alon Barad
Alon Barad
Software Engineer

Oct 3, 2026·6 min read·3 visits

Executive Summary (TL;DR)

The Trigger.dev CLI v3 exposed plaintext environment variables and sensitive API keys in stdout during build deployments when debug logging was enabled. Upgrading to version v4.5.9 or later resolves the vulnerability by implementing a strict metadata-only allowlist log handler.

A sensitive information disclosure vulnerability exists in the Trigger.dev Command Line Interface (CLI) framework. When executing build processes inside CLI v3 packages, the framework's debug deployment logs print unredacted, resolved environment variables and secrets to standard output or log streams. This exposure occurs when the CLI is operated with a high logging verbosity level, enabling any individual or automated system with read access to build logs, CI/CD output consoles, or local development streams to capture plaintext sensitive parameters, such as database credentials, API keys, and private external integration tokens.

Vulnerability Overview

The Trigger.dev framework relies on background workers compiled at deployment runtime. The CLI utility manages compiling, bundling, and pushing these execution units to their respective orchestrators. Because background workers interface with numerous third-party systems, they require environment variables, database configuration profiles, and credentials. During compilation, the CLI v3 sub-package parses local files and remote configuration stores to establish compilation parameters.

A security advisory, identified as GHSA-FJ2X-MQQP-3V2W, details an information exposure vulnerability inside this build pipeline. The issue stems from verbose debugging logs produced by the build worker initialization routine. When developers execute deployment scripts with elevated debugging flags, the tool dumps configuration options directly to console output. This dumping behavior exposes highly sensitive variables and credentials.

The vulnerability resides in the @trigger.dev/cli package, specifically impacting CLI v3 packages located in packages/cli-v3. The primary attack surface exists anywhere console logs are recorded, including CI/CD output interfaces and logging platforms. Any actor or automated system with viewing permissions to these logs can capture plaintext secrets without additional authentication or authorization.

Root Cause Analysis

At the core of GHSA-FJ2X-MQQP-3V2W is a design pattern that directly serializes a broad configuration object without sanitization or selective parsing. The CLI’s compilation worker, initialized via the buildWorker function in packages/cli-v3/src/build/buildWorker.ts, consumes an object of type BuildWorkerOptions. This object serves as a comprehensive container for deployment targets, branches, path maps, and an envVars record storing key-value secret strings.

During development, logging statements were integrated at critical lifecycle points to assist with diagnostics and troubleshooting. A debug log entry was implemented using logger.debug("Starting buildWorker", { options }) to capture the worker's initial state. Because this logger accepts arbitrary objects and converts them to JSON, the entire configuration block, including the decrypted environment variables, was written to stdout.

This mechanism violates CWE-532: Insertion of Sensitive Information into Log File. The vulnerability becomes active whenever the log level is configured to capture debug statements, a common troubleshooting practice. The lack of an input-filtering or output-redaction layer allowed secrets to escape memory protections and enter persistent log streams.

Code Analysis

The vulnerable implementation of buildWorker.ts highlights the risk of passing unvetted objects to logging interfaces. The original code path directly serialized the options parameter, writing it to the console. The following snippet illustrates this insecure logging pattern prior to remediation:

// Vulnerable implementation in packages/cli-v3/src/build/buildWorker.ts
export async function buildWorker(options: BuildWorkerOptions) {
  logger.debug("Starting buildWorker", {
    options, // Directly serializes the unredacted options block
  });
  
  const resolvedConfig = options.resolvedConfig;
  // ... remaining compilation logic continues
}

To address this, the maintainers separated logging concerns from the execution context. They created a dedicated file, packages/cli-v3/src/build/buildWorkerLogging.ts, and defined a strict schema for capturing parameters. The updated code maps and records only the counts of sensitive keys and safe configuration metadata.

// Patched implementation in packages/cli-v3/src/build/buildWorkerLogging.ts
import { logger } from "../utilities/logger.js";
 
type BuildWorkerLogOptions = {
  target: string;
  branch?: string;
  envVars?: Record<string, string>;
  rewritePaths?: boolean;
  forcedExternals?: string[];
  plain?: boolean;
};
 
export function logBuildWorkerStart(options: BuildWorkerLogOptions) {
  logger.debug("Starting buildWorker", {
    target: options.target,
    hasBranch: options.branch !== undefined,
    envVarCount: Object.keys(options.envVars ?? {}).length, // Captures only variable quantity
    rewritePaths: options.rewritePaths ?? false,
    forcedExternalsCount: options.forcedExternals?.length ?? 0,
    plain: options.plain ?? false,
  });
}

This architectural change introduces an explicit structural allowlist. The main execution path in buildWorker.ts now calls logBuildWorkerStart(options) instead of writing raw configurations. This ensures that new configuration parameters added to the build sequence will not inadvertently leak secrets.

Exploitation & Attack Scenarios

Exploiting this vulnerability does not require complex payloads or network exploitation techniques. It is a passive exposure scenario that relies on access to output buffers or log file stores. In typical enterprise setups, deployment commands are automated within CI/CD pipelines such as GitHub Actions, GitLab CI, or Jenkins.

To troubleshoot packaging or integration issues, administrators often enable verbosity flags such as trigger.dev deploy --log-level debug. When this occurs, the runner processes the CLI command, serializes the secrets, and outputs them to the runner's execution console. Any user or system with read-only access to the pipeline history can retrieve the plaintext credentials.

The risk is exacerbated when logging outputs are synchronized to third-party log aggregators, security information and event management (SIEM) engines, or public storage buckets. Because the logs contain structured JSON, automated scrapers can easily identify patterns such as STRIPE_API_KEY, DATABASE_URL, or OPENAI_API_KEY. Once harvested, these credentials can be used to pivot into deeper production architectures.

Impact Assessment

The security impact of GHSA-FJ2X-MQQP-3V2W is classified as severe information leakage. Because the CLI is used to compile backend workflows, the leaked secrets often represent highly critical credentials. This includes administrative database connection parameters, live payment processor integration keys, and cloud infrastructure service tokens.

Compromise of these secrets can result in full data exfiltration, service disruption, and financial loss. The vulnerability has an indirect but substantial impact on systems trust and regulatory compliance. Organizations subject to standards such as PCI-DSS or GDPR face immediate compliance failures if cryptographic keys or personal credentials are discovered in plain logs.

The CVSS score is established as 7.5 (High) under the assumption that the log outputs are stored in accessible build history consoles. The exploit maturity remains low since active external vectors are not required to trigger the leak. Security teams should treat any verbose log output generated before the patch as a potential breach and rotate all involved tokens immediately.

Remediation & Mitigation Guidance

To resolve this security issue, organizations must immediately upgrade the @trigger.dev/cli package to version v4.5.9 or later. This release completely deprecates the raw serialization of build worker parameters in favor of the sanitized logging structure. Running standard dependency updates in the project's root folder will resolve the exposure.

# Upgrade commands for different package managers
npm install @trigger.dev/cli@latest --save-dev
pnpm add @trigger.dev/cli@latest -D
yarn add @trigger.dev/cli@latest --dev

If immediate upgrading is not feasible, organizations should configure deployment agents to restrict log verbosity. Administrators must audit deployment configurations to verify that --log-level debug or verbose environments are disabled. Additionally, CI/CD platform features such as secret masking should be implemented to catch and redact sensitive strings.

Finally, security engineers must run retroactive log audits. Search historical log archives for the string "Starting buildWorker" and inspect the trailing JSON parameters. If plaintext database credentials or API tokens are discovered in the output history, those secrets must be rotated immediately.

Fix Analysis (1)

Technical Appendix

CVSS Score
7.5/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Systems

Trigger.dev CLI packages (@trigger.dev/cli v3)

Affected Versions Detail

Product
Affected Versions
Fixed Version
@trigger.dev/cli
Trigger.dev
< 4.5.94.5.9
AttributeDetail
CWE IDCWE-532
Attack VectorLocal / Log Access
CVSS7.5 (High)
Exploit StatusProof of Concept (Unit Tests)
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1552Unsecured Credentials
Credential Access
T1552.001Credentials in Files
Credential Access
T1592Gather Victim Host Information
Reconnaissance
CWE-532
Insertion of Sensitive Information into Log File

The product writes sensitive information to log files, which can allow attackers to obtain credentials or other sensitive information.

Vulnerability Timeline

Security patch commit 878c15811aca8339a751aa0c2211012db7a47ce5 created and merged
2026-07-29
Release v4.5.9 published on GitHub
2026-07-29
Vulnerability details researched and disclosed
2026-10-01

References & Sources

  • [1]GitHub Security Advisory GHSA-FJ2X-MQQP-3V2W
  • [2]Fix Commit
  • [3]Pull Request #4420
  • [4]Release v4.5.9

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•19 minutes ago•CVE-2026-18140
7.5

CVE-2026-18140: Uncontrolled Recursion in aws-smithy-json Token Skipping Path

CVE-2026-18140 is a denial-of-service vulnerability in the Amazon aws-smithy-json Rust crate. Under-validation of recursion depth within the unknown-key skipping path allows a remote, unauthenticated attacker to cause stack exhaustion and process aborts by sending deeply nested JSON arrays.

Amit Schendel
Amit Schendel
2 views•6 min read
•about 3 hours ago•CVE-2026-104855
2.0

CVE-2026-104855: Sandbox Escape via Reentrant State Desynchronization in Wasmtime Bulk Memory Operations

CVE-2026-104855 is a critical vulnerability involving a race condition and reentrant state desynchronization within Wasmtime, a standalone WebAssembly runtime. Due to incremental mid-operation preemption points in compiler-generated loops for bulk memory and table operations, a host-defined epoch or fuel deadline callback could mutate the WebAssembly Store. Upon resuming, the virtual machine utilized stale cached pointers, resulting in use-after-free, out-of-bounds writes, and sandbox escape.

Amit Schendel
Amit Schendel
3 views•7 min read
•about 4 hours ago•CVE-2026-74802
8.2

CVE-2026-74802: Cross-Site WebSocket Hijacking (CSWSH) in SiYuan Knowledge Workspace

CVE-2026-74802 is a critical Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the SiYuan knowledge workspace application. Due to improper origin validation across multiple internal WebSocket endpoints, an attacker can hijack active authenticated sessions when a victim visits an untrusted external page. This allows the attacker to route malicious network traffic through the victim's localized SiYuan server, establishing an authenticated network pivot and facilitating Server-Side Request Forgery (SSRF).

Alon Barad
Alon Barad
4 views•5 min read
•about 5 hours ago•CVE-2026-74904
8.7

CVE-2026-74904: Missing Authorization in SiYuan Note-Taking Application API

A high-severity missing authorization vulnerability (CWE-862) exists in the SiYuan note-taking application before v3.7.4. Seventeen block metadata and content-derived endpoints within kernel/api/block.go lack proper publish-access and role-based checks. This allows low-privilege or anonymous users in publish mode to bypass workspace restrictions and disclose private block content, trace workspace structures, map document indexes, and verify the existence of private notes. The vulnerability is addressed in version v3.7.4.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 6 hours ago•CVE-2026-71416
8.8

CVE-2026-71416: Cross-Site WebSocket Hijacking in Headroom Proxy Server

A critical cross-site WebSocket hijacking (CSWSH) vulnerability in headroomlabs-ai/headroom prior to version 0.35.0 allows unauthorized external origins to establish connection channels to the Headroom proxy, enabling arbitrary prompt execution and remote code execution through local tool integration.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 7 hours ago•GHSA-CJCG-CXMH-9WCR
7.5

GHSA-cjcg-cxmh-9wcr: Unbounded Memory Allocation via HTTP/2 Bomb in praxis-proxy

A critical vulnerability exists in the praxis-proxy library where the omission of default limits on HTTP/2 server options allows remote attackers to trigger a Denial of Service (DoS) using an HPACK compression bomb and flow-control window stalls. This vulnerability is cataloged as GHSA-cjcg-cxmh-9wcr.

Amit Schendel
Amit Schendel
5 views•7 min read