{"id":"GHSA-59h8-w5q6-mfmp","summary":"Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId","details":"## Summary\n\nThe POST handler for `/realtime/v1/streams/:runId/:streamId` has no authentication. Any entity that knows or guesses a run friendlyId can inject arbitrary data into its realtime stream.\n\n## Vulnerability Details\n\n**File:** `apps/webapp/app/routes/realtime.v1.streams.$runId.$streamId.ts`\n\nThe `action` handler (line 17) has no auth wrapper. The code comment says: \"Plain action for backwards compatibility with older clients that don't send auth headers.\"\n\nThe run lookup at line 29 uses `where: { friendlyId: runId }` with NO environment scoping (`runtimeEnvironmentId` is not checked), so production runs are accessible.\n\nRun friendlyIds follow predictable patterns (e.g., `run_1234abcd`).\n\n## Steps to Reproduce\n\n```bash\n# No authentication required\ncurl -X POST \"http://localhost:8030/realtime/v1/streams/run_KNOWN_ID/stream_1\"   -H \"Content-Type: application/json\"   -d '{\"injected\": \"data\"}'\n```\n\n## Impact\n\nUnauthenticated data injection into any run realtime stream. Cross-environment access (no scoping).","modified":"2026-10-02T23:00:20.889642627Z","published":"2026-10-02T22:39:57Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-02T22:39:57Z","nvd_published_at":null,"cwe_ids":["CWE-306"]},"references":[{"type":"WEB","url":"https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-59h8-w5q6-mfmp"},{"type":"WEB","url":"https://github.com/triggerdotdev/trigger.dev/pull/4250"},{"type":"WEB","url":"https://github.com/triggerdotdev/trigger.dev/commit/73d966ad226548b5f96fb5b4fc6fa607a3b7b8f8"},{"type":"PACKAGE","url":"https://github.com/triggerdotdev/trigger.dev"},{"type":"WEB","url":"https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.5"}],"affected":[{"package":{"name":"trigger.dev","ecosystem":"npm","purl":"pkg:npm/trigger.dev"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.5.5"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 4.5.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-59h8-w5q6-mfmp/GHSA-59h8-w5q6-mfmp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}