rootpwn

high · CVSS v3 7.1 · CVSS v4 7.1

CVE-2026-92773

An authorization verification flaw in Trigger.dev prior to version 4.6.0 allows authenticated users to improperly bind GitHub App installati

Overview

An authorization verification flaw in Trigger.dev prior to version 4.6.0 allows authenticated users to improperly bind GitHub App installations to their own organization. By replaying state cookies and manipulating installation identifiers during setup, an attacker can hijack another entity's GitHub App integration. This grants unauthorized access to repositories connected to the targeted installation.

Description

Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying state cookies and supplying sequential installation identifiers, gaining unauthorized access to the victim's repositories.

Impact

Impacts organizations operating Trigger.dev instances with GitHub App integrations. Successful exploitation leads to compromised confidentiality and integrity by exposing connected GitHub repositories to unauthorized users.

Remediation

Upgrade Trigger.dev instances to version 4.6.0 or later. Audit all current GitHub App installations and linked organization accounts within Trigger.dev to detect and revoke any unauthorized integrations.

Risk context

Evaluated with a High severity rating (CVSS 7.1) and no current EPSS score. Patching should be prioritized for environments relying on GitHub integrations to prevent unauthorized cross-organization access.

Affected products

  • Trigger.dev Trigger.dev (< 4.6.0)

Scores

Severity
high
CVSS v2
5.6
CVSS v3
7.1
CVSS v4
7.1
EPSS

Trigger.dev GitHub Integration Authorization Bypass Access Control Patch Management CVE-2026-92773

← All CVEs