GHSA-9q4r-4842-93vw
### Summary A cross-tenant SQL injection in the TSQL query compiler lets **any authenticated trigger.dev customer read every other tenant's analytics data**. The customer-facing query endpoint `POST /api/v1/query` accepts a TSQL/TRQL query that is compiled to ClickHouse SQL by `internal-packages/tsql`. The compiler parameterizes or escapes all user input and injects a per-tenant `WHERE` guard — **except the window-function name**, which is concatenated into the SQL string with no allowlist and no escaping. By smuggling a backtick-quoted identifier into that position, an attacker injects a raw subquery (e.g. `(SELECT ... FROM task_runs_v2 WHERE organization_id = 'org_VICTIM')`) that sits **outside** the tenant guard, exfiltrating another organization's rows. Verified end-to-end against the real compiler and a live ClickHouse. ### Details **Vulnerable sink** — `internal-packages/tsql/src/query/printer.ts:3073-3075`, `ClickHousePrinter.visitWindowFunction`: ```ts private visitWindowFunction(node: WindowFunction): string { const args = node.args ? node.args.map((a) => this.visit(a)) : []; const funcCall = `${node.name}(${args.join(", ")})`; // <-- node.name concatenated RAW ... } ``` `node.name` is emitted directly into the SQL with **no allowlist check and no identifier escaping**. This is the only place in the compiler where an attacker-influenced identifier reaches the output unguarded: - The normal function-call path `visitCall` (`printer.ts:2951`) throws `Unknown function` for any name outside the hardcoded `TSQL_CLICKHOUSE_FUNCTIONS` / `TSQL_AGGREGATIONS` allowlists — **this gate is absent on the window-function path**. - String constants are bound as ClickHouse `query_params` (parameterized). - Other identifiers go through `escapeClickHouseIdentifier`. - Table functions (`url()/file()/remote()/s3()`) are rejected. A **backtick-quoted identifier** is accepted by the lexer and **unescaped** into `node.name` by `visitIdentifier` (the backticks are str
Properties
- summary
- Trigger.dev: Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function name
- severity
- high
- cvss_score
- 7.7
- retrieved_at
- 2026-10-03T18:15:00+00:00
- ghsa_published
- 2026-10-02T22:42:20Z
- source_url
- https://github.com/advisories/GHSA-9q4r-4842-93vw
- ghsa_updated
- 2026-10-02T22:42:23Z
- ghsa_id
- GHSA-9q4r-4842-93vw
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-9q4r-4842-93vw
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- signal_observed_at
- 2026-10-03T01:59:23+00:00
- is_ghsa_only
- true
Related Entities (5)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
Explore deeper with Ninja Signal's threat intelligence graph