GHSA-59h8-w5q6-mfmp
## Summary The POST handler for `/realtime/v1/streams/:runId/:streamId` has no authentication. Any entity that knows or guesses a run friendlyId can inject arbitrary data into its realtime stream. ## Vulnerability Details **File:** `apps/webapp/app/routes/realtime.v1.streams.$runId.$streamId.ts` The `action` handler (line 17) has no auth wrapper. The code comment says: "Plain action for backwards compatibility with older clients that don't send auth headers." The run lookup at line 29 uses `where: { friendlyId: runId }` with NO environment scoping (`runtimeEnvironmentId` is not checked), so production runs are accessible. Run friendlyIds follow predictable patterns (e.g., `run_1234abcd`). ## Steps to Reproduce ```bash # No authentication required curl -X POST "http://localhost:8030/realtime/v1/streams/run_KNOWN_ID/stream_1" -H "Content-Type: application/json" -d '{"injected": "data"}' ``` ## Impact Unauthenticated data injection into any run realtime stream. Cross-environment access (no scoping).
Properties
- severity
- medium
- summary
- Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId
- cvss_score
- 5.3
- retrieved_at
- 2026-10-03T18:15:00+00:00
- ghsa_published
- 2026-10-02T22:39:57Z
- source_url
- https://github.com/advisories/GHSA-59h8-w5q6-mfmp
- ghsa_updated
- 2026-10-02T22:39:57Z
- ghsa_id
- GHSA-59h8-w5q6-mfmp
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-59h8-w5q6-mfmp
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- signal_observed_at
- 2026-10-03T01:59:23+00:00
- is_ghsa_only
- true
Related Entities (4)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph