high · CVSS v3 7.1 · CVSS v4 7.1
CVE-2026-92773
An authorization verification flaw in Trigger.dev prior to version 4.6.0 allows authenticated users to improperly bind GitHub App installati
Overview
An authorization verification flaw in Trigger.dev prior to version 4.6.0 allows authenticated users to improperly bind GitHub App installations to their own organization. By replaying state cookies and manipulating installation identifiers during setup, an attacker can hijack another entity's GitHub App integration. This grants unauthorized access to repositories connected to the targeted installation.
Description
Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying state cookies and supplying sequential installation identifiers, gaining unauthorized access to the victim's repositories.
Impact
Impacts organizations operating Trigger.dev instances with GitHub App integrations. Successful exploitation leads to compromised confidentiality and integrity by exposing connected GitHub repositories to unauthorized users.
Remediation
Upgrade Trigger.dev instances to version 4.6.0 or later. Audit all current GitHub App installations and linked organization accounts within Trigger.dev to detect and revoke any unauthorized integrations.
Risk context
Evaluated with a High severity rating (CVSS 7.1) and no current EPSS score. Patching should be prioritized for environments relying on GitHub integrations to prevent unauthorized cross-organization access.
Affected products
- Trigger.dev Trigger.dev (< 4.6.0)
Scores
- Severity
- high
- CVSS v2
- 5.6
- CVSS v3
- 7.1
- CVSS v4
- 7.1
- EPSS
- —