mediumCVSS 5.5Vulnerability

GHSA-fj2x-mqqp-3v2w

Affected version: trigger.dev 4.5.3 (4.5.6 was advertised by the CLI but was not tested). A staging dry-run executed with `trigger.dev deploy --env staging --dry-run --log-level debug`. The debug output logged the complete build-worker options object. Its `envVars` property contained unredacted values for every resolved staging variable, including database connection strings and service credentials. The non-debug environment listing correctly hides values, so users can reasonably expect deployment logs not to print secrets. Impact: anyone with access to a developer terminal transcript, CI debug log, captured agent/tool output, or support bundle can recover deployment secrets even though no deployment occurs. Reproduction: 1. Configure a Trigger.dev project with a secret environment variable. 2. Run the command above with an authenticated profile. 3. Inspect the `Starting buildWorker` debug record. 4. `options.envVars` contains the plaintext value. No real credential is included in this report. The observed customer credentials are being rotated separately. Suggested remediation: never serialize `envVars` values in debug output; log names only or replace every value with a fixed marker. Add regression coverage for deploy, dry-run, and debug logging, and review adjacent debug records for resolved secrets.

Properties

severity
medium
summary
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values
cvss_score
5.5
retrieved_at
2026-10-03T18:15:00+00:00
ghsa_published
2026-10-02T22:45:12Z
source_url
https://github.com/advisories/GHSA-fj2x-mqqp-3v2w
ghsa_updated
2026-10-02T22:45:13Z
ghsa_id
GHSA-fj2x-mqqp-3v2w
last_source
GitHub Advisory Database
cve_id
GHSA-fj2x-mqqp-3v2w
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
true

Related Entities (4)

VULNERABLE_TO (1)

←[Software]npm/trigger.dev

AFFECTS (1)

→[Software]npm/trigger.dev

HAS_WEAKNESS (1)

→[Weakness]Insertion of Sensitive Information into Log File

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph