Sanaan Fayaz Wani

GHSA-59h8-w5q6-mfmp

Unauthenticated Realtime Stream Data Injection via Run FriendlyId

—

GHSA-59h8-w5q6-mfmp

Published, fixed and credited. Root cause, the vulnerable code, reproduction and the fix, as published in the advisory itself.

   
Advisory GHSA-59h8-w5q6-mfmp
CVE not assigned
Severity Medium (5.3)
CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE CWE-306 (Missing Authentication for Critical Function)
Published 2026-07-21

Affected versions

Package Ecosystem Vulnerable Fixed in
trigger.dev npm <= 4.5.4 n/a

Summary

The POST handler for /realtime/v1/streams/:runId/:streamId has no authentication. Any entity that knows or guesses a run friendlyId can inject arbitrary data into its realtime stream.

Vulnerability Details

File: apps/webapp/app/routes/realtime.v1.streams.$runId.$streamId.ts

The action handler (line 17) has no auth wrapper. The code comment says: “Plain action for backwards compatibility with older clients that don’t send auth headers.”

The run lookup at line 29 uses where: { friendlyId: runId } with NO environment scoping (runtimeEnvironmentId is not checked), so production runs are accessible.

Run friendlyIds follow predictable patterns (e.g., run_1234abcd).

Steps to Reproduce

# No authentication required
curl -X POST "http://localhost:8030/realtime/v1/streams/run_KNOWN_ID/stream_1"   -H "Content-Type: application/json"   -d '{"injected": "data"}'

Impact

Unauthenticated data injection into any run realtime stream. Cross-environment access (no scoping).

About this writeup

Sanaan Fayaz Wani (GitHub sfwani) reported this vulnerability to the trigger.dev maintainers under coordinated disclosure and is credited as a reporter in GHSA-59h8-w5q6-mfmp, published 2026-07-21.

All published findings: advisory index.