highCVSS 7.1Vulnerability

GHSA-pp95-gc86-jq6q

### Summary The run replay `action` function at `apps/webapp/app/routes/resources.taskruns.$runParam.replay.ts` has no authentication or authorization check. While the `loader` (GET) in the same file properly calls `requireUser(request)` and scopes queries to the user's organizations, the `action` (POST) at line 166 does neither — allowing any authenticated user to replay task runs from any organization by knowing the run's `friendlyId`. ### Details **Vulnerable file:** `apps/webapp/app/routes/resources.taskruns.$runParam.replay.ts` **The `loader` (line 28-29) — properly authenticated:** ```typescript export async function loader({ request, params }: LoaderFunctionArgs) { const user = await requireUser(request); // ✓ Auth check const userId = user.id; // ... queries scoped to user's orgs } ``` **The `action` (line 166-193) — NO authentication:** ```typescript export const action: ActionFunction = async ({ request, params }) => { const { runParam } = ParamSchema.parse(params); // ✗ NO requireUser() call // ✗ NO requireUserId() call // ✗ NO org membership check const taskRun = await prisma.taskRun.findFirst({ where: { friendlyId: runParam, // Queries ANY run, no org scoping }, include: { runtimeEnvironment: { select: { slug: true } }, project: { include: { organization: true } }, }, }); // ... proceeds to replay the run in the victim's environment const replayRunService = new ReplayTaskRunService(); ``` The Prisma query at line 177 fetches the run by `friendlyId` only — no `userId` or organization filter. The `ReplayTaskRunService` then creates a new task run in the victim's environment, executing with the victim's environment variables and secrets. **Same bug class exists in:** `apps/webapp/app/routes/resources.batches.$batchId.check-completion.ts` (line 17) — the `action` has zero authentication, allowing any user to trigger batch completion for any batch ID. ### PoC **Run replay IDOR:** ```bash #

Properties

summary
Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR)
severity
high
cvss_score
7.1
retrieved_at
2026-10-03T18:15:00+00:00
ghsa_published
2026-10-02T22:35:24Z
source_url
https://github.com/advisories/GHSA-pp95-gc86-jq6q
ghsa_updated
2026-10-02T22:35:26Z
ghsa_id
GHSA-pp95-gc86-jq6q
last_source
GitHub Advisory Database
cve_id
GHSA-pp95-gc86-jq6q
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
true

Related Entities (4)

AFFECTS (1)

→[Software]npm/trigger.dev

HAS_WEAKNESS (1)

→[Weakness]Missing Authorization

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/trigger.dev

Explore deeper with Ninja Signal's threat intelligence graph