criticalVulnerability

GHSA-gg6r-gp4c-89hp

## TL;DR The /coordinator Socket.IO namespace mounts on every webapp boot and authenticates with a default secret ("coordinator-secret") baked into source. The override variable isn't documented in the self-host docs, .env.example, or helm values, so any operator who didn't read source ships with the default. Once connected, READY_FOR_EXECUTION returns the run's decrypted env vars. Anyone who can reach a default-config self-hosted webapp can pull production secrets out of any run whose internal id they can find. ## Vulnerabilities This attack is made possible by 3 vulnerabilities in Trigger.dev: ### 1. Hardcoded default authentication secret (CWE-798, Critical) PROVIDER_SECRET and COORDINATOR_SECRET are declared with `.default("provider-secret")` / `.default("coordinator-secret")` in [`apps/webapp/app/env.server.ts:289-290`](https://github.com/triggerdotdev/trigger.dev/blob/v4.4.4/apps/webapp/app/env.server.ts#L289-L290). The values are present in the public source repo, neither var is documented in `docs/self-hosting/env/*.mdx`, `hosting/docker/.env.example`, or `hosting/k8s/helm/values.yaml`, and the auth check at [`packages/core/src/v3/zodNamespace.ts:148`](https://github.com/triggerdotdev/trigger.dev/blob/v4.4.4/packages/core/src/v3/zodNamespace.ts#L148) is a plain string compare against that published value ### 2. Coordinator handler returns decrypted env vars to any authenticated caller (CWE-200, High) `READY_FOR_EXECUTION` at [`apps/webapp/app/v3/handleSocketIo.server.ts:123`](https://github.com/triggerdotdev/trigger.dev/blob/v4.4.4/apps/webapp/app/v3/handleSocketIo.server.ts#L123) calls `sharedQueueTasks.getLatestExecutionPayloadFromRun(runId, ...)`, which at [`apps/webapp/app/v3/marqs/sharedQueueConsumer.server.ts:1881-1895`](https://github.com/triggerdotdev/trigger.dev/blob/v4.4.4/apps/webapp/app/v3/marqs/sharedQueueConsumer.server.ts#L1881-L1895) returns `payload.environment` as the run's decrypted env-var dictionary. Any internal runId is enough to

Properties

ghsa_id
GHSA-gg6r-gp4c-89hp
severity
critical
summary
Trigger.dev: V1 coordinator default-secret unauth Socket.IO
last_source
GitHub Advisory Database
cve_id
GHSA-gg6r-gp4c-89hp
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
true
retrieved_at
2026-10-03T18:15:00+00:00
ghsa_published
2026-10-02T22:39:00Z
source_url
https://github.com/advisories/GHSA-gg6r-gp4c-89hp
ghsa_updated
2026-10-02T22:39:02Z

Related Entities (6)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/trigger.dev

AFFECTS (1)

→[Software]npm/trigger.dev

HAS_WEAKNESS (3)

→[Weakness]Exposure of Sensitive Information to an Unauthorized Actor
→[Weakness]Missing Authorization
→[Weakness]Use of Hard-coded Credentials

Explore deeper with Ninja Signal's threat intelligence graph