mediumCVSS 5.3Vulnerability

GHSA-59h8-w5q6-mfmp

## Summary The POST handler for `/realtime/v1/streams/:runId/:streamId` has no authentication. Any entity that knows or guesses a run friendlyId can inject arbitrary data into its realtime stream. ## Vulnerability Details **File:** `apps/webapp/app/routes/realtime.v1.streams.$runId.$streamId.ts` The `action` handler (line 17) has no auth wrapper. The code comment says: "Plain action for backwards compatibility with older clients that don't send auth headers." The run lookup at line 29 uses `where: { friendlyId: runId }` with NO environment scoping (`runtimeEnvironmentId` is not checked), so production runs are accessible. Run friendlyIds follow predictable patterns (e.g., `run_1234abcd`). ## Steps to Reproduce ```bash # No authentication required curl -X POST "http://localhost:8030/realtime/v1/streams/run_KNOWN_ID/stream_1" -H "Content-Type: application/json" -d '{"injected": "data"}' ``` ## Impact Unauthenticated data injection into any run realtime stream. Cross-environment access (no scoping).

Properties

severity
medium
summary
Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId
cvss_score
5.3
retrieved_at
2026-10-03T18:15:00+00:00
ghsa_published
2026-10-02T22:39:57Z
source_url
https://github.com/advisories/GHSA-59h8-w5q6-mfmp
ghsa_updated
2026-10-02T22:39:57Z
ghsa_id
GHSA-59h8-w5q6-mfmp
last_source
GitHub Advisory Database
cve_id
GHSA-59h8-w5q6-mfmp
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
true

Related Entities (4)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/trigger.dev

AFFECTS (1)

→[Software]npm/trigger.dev

HAS_WEAKNESS (1)

→[Weakness]Missing Authentication for Critical Function

Explore deeper with Ninja Signal's threat intelligence graph