mediumCVSS 5.4Vulnerability

GHSA-4672-hwv6-gq62

### Summary Trigger.dev isolates each project into multiple **environments** (`dev`, `staging`, `prod`, and per-PR `preview` branches), each with its **own secret API key** — the environment is a trust boundary (a `dev`/preview/CI key is lower-trust than a `prod` key). Most API routes enforce this by scoping resource lookups to the authenticated key's environment (`where: { friendlyId, runtimeEnvironmentId: auth.environment.id }`). The deployment **cancel** path does not. `DeploymentService.getDeployment()` scopes the lookup by **`projectId` only** — never `environmentId` — so a secret key for *any* environment in a project can cancel a deployment belonging to *any other* environment of the same project, including **production**. The deployment **GET** route, by contrast, *is* env-scoped — so the same key that is **404'd when trying to read** a prod deployment can nonetheless **cancel** it. That asymmetry is the bug. ### Affected `apps/webapp`, HEAD `5d99457` (current `main`). Affects self-hosted and cloud. ### Root cause `apps/webapp/app/routes/api.v1.deployments.$deploymentId.cancel.ts` authenticates to an environment and calls `deploymentService.cancelDeployment(authenticatedEnv, deploymentId, ...)`. `apps/webapp/app/v3/services/deployment.server.ts`: ```ts public cancelDeployment(authenticatedEnv: Pick<AuthenticatedEnvironment,"projectId">, friendlyId, ...) { return this.getDeployment(authenticatedEnv.projectId, friendlyId) // projectId only .andThen(validateDeployment) // rejects only FINAL statuses .andThen(cancelDeployment); // updateMany -> status CANCELED } private getDeployment(projectId: string, friendlyId: string) { return this._prisma.workerDeployment.findFirst({ where: { friendlyId, projectId }, // <-- NO environmentId filter }); } ``` `cancelDeployment` accepts `authenticatedEnv` but its type is literally `Pick<AuthenticatedEnvironment,"projec

Properties

severity
medium
summary
Trigger.dev: Cross-environment deployment cancel
cvss_score
5.4
retrieved_at
2026-10-03T18:15:00+00:00
ghsa_published
2026-10-02T22:42:40Z
source_url
https://github.com/advisories/GHSA-4672-hwv6-gq62
ghsa_updated
2026-10-02T22:42:43Z
ghsa_id
GHSA-4672-hwv6-gq62
last_source
GitHub Advisory Database
cve_id
GHSA-4672-hwv6-gq62
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
true

Related Entities (4)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/trigger.dev

AFFECTS (1)

→[Software]npm/trigger.dev

HAS_WEAKNESS (1)

→[Weakness]Authorization Bypass Through User-Controlled Key

Explore deeper with Ninja Signal's threat intelligence graph