HIGHVulnerability

CVE-2026-85651

Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to consume victim resources and pollute run history.

Properties

severity
HIGH
score
8.5
cve_id
CVE-2026-85651
signal_observed_at
2026-09-16T13:31:01+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
published_at
2026-09-04T15:17:43.347
last_modified
2026-09-10T16:18:00.370

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85651 — Ninja Signal Threat Intelligence | Ninja Signal