Trigger.dev Cross-Tenant Task Run Replay via Missing Environment Scope Check (IDOR)
mediumAgentPrivilege AbuseTrigger.dev's run replay API looks up task runs by a friendly ID without checking that the run belongs to the caller's environment/tenant, allowing any valid API key holder to replay another tenant's agent task run. This lets an attacker consume victim compute resources and repeat side effects of that run, and in combination with a separate object-store path-traversal bug, potentially inject attacker-controlled payload bytes into the victim's replayed task. The issue is fixed in 4.5.0-rc.4.
Updated Aug 15, 2026 · CVSS 4.2