highCVSS 7.7Vulnerability

GHSA-9q4r-4842-93vw

### Summary A cross-tenant SQL injection in the TSQL query compiler lets **any authenticated trigger.dev customer read every other tenant's analytics data**. The customer-facing query endpoint `POST /api/v1/query` accepts a TSQL/TRQL query that is compiled to ClickHouse SQL by `internal-packages/tsql`. The compiler parameterizes or escapes all user input and injects a per-tenant `WHERE` guard — **except the window-function name**, which is concatenated into the SQL string with no allowlist and no escaping. By smuggling a backtick-quoted identifier into that position, an attacker injects a raw subquery (e.g. `(SELECT ... FROM task_runs_v2 WHERE organization_id = 'org_VICTIM')`) that sits **outside** the tenant guard, exfiltrating another organization's rows. Verified end-to-end against the real compiler and a live ClickHouse. ### Details **Vulnerable sink** — `internal-packages/tsql/src/query/printer.ts:3073-3075`, `ClickHousePrinter.visitWindowFunction`: ```ts private visitWindowFunction(node: WindowFunction): string { const args = node.args ? node.args.map((a) => this.visit(a)) : []; const funcCall = `${node.name}(${args.join(", ")})`; // <-- node.name concatenated RAW ... } ``` `node.name` is emitted directly into the SQL with **no allowlist check and no identifier escaping**. This is the only place in the compiler where an attacker-influenced identifier reaches the output unguarded: - The normal function-call path `visitCall` (`printer.ts:2951`) throws `Unknown function` for any name outside the hardcoded `TSQL_CLICKHOUSE_FUNCTIONS` / `TSQL_AGGREGATIONS` allowlists — **this gate is absent on the window-function path**. - String constants are bound as ClickHouse `query_params` (parameterized). - Other identifiers go through `escapeClickHouseIdentifier`. - Table functions (`url()/file()/remote()/s3()`) are rejected. A **backtick-quoted identifier** is accepted by the lexer and **unescaped** into `node.name` by `visitIdentifier` (the backticks are str

Properties

summary
Trigger.dev: Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function name
severity
high
cvss_score
7.7
retrieved_at
2026-10-03T18:15:00+00:00
ghsa_published
2026-10-02T22:42:20Z
source_url
https://github.com/advisories/GHSA-9q4r-4842-93vw
ghsa_updated
2026-10-02T22:42:23Z
ghsa_id
GHSA-9q4r-4842-93vw
last_source
GitHub Advisory Database
cve_id
GHSA-9q4r-4842-93vw
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
true

Related Entities (5)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/trigger.dev

AFFECTS (1)

→[Software]npm/trigger.dev

HAS_WEAKNESS (2)

→[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
→[Weakness]Authorization Bypass Through User-Controlled Key

Explore deeper with Ninja Signal's threat intelligence graph