{"id":"GHSA-fj2x-mqqp-3v2w","summary":"Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values","details":"Affected version: trigger.dev 4.5.3 (4.5.6 was advertised by the CLI but was not tested).\n\nA staging dry-run executed with `trigger.dev deploy --env staging --dry-run --log-level debug`. The debug output logged the complete build-worker options object. Its `envVars` property contained unredacted values for every resolved staging variable, including database connection strings and service credentials. The non-debug environment listing correctly hides values, so users can reasonably expect deployment logs not to print secrets.\n\nImpact: anyone with access to a developer terminal transcript, CI debug log, captured agent/tool output, or support bundle can recover deployment secrets even though no deployment occurs.\n\nReproduction:\n1. Configure a Trigger.dev project with a secret environment variable.\n2. Run the command above with an authenticated profile.\n3. Inspect the `Starting buildWorker` debug record.\n4. `options.envVars` contains the plaintext value.\n\nNo real credential is included in this report. The observed customer credentials are being rotated separately.\n\nSuggested remediation: never serialize `envVars` values in debug output; log names only or replace every value with a fixed marker. Add regression coverage for deploy, dry-run, and debug logging, and review adjacent debug records for resolved secrets.","modified":"2026-10-02T23:00:21.844658364Z","published":"2026-10-02T22:45:12Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-532"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-02T22:45:12Z"},"references":[{"type":"WEB","url":"https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-fj2x-mqqp-3v2w"},{"type":"WEB","url":"https://github.com/triggerdotdev/trigger.dev/pull/4420"},{"type":"WEB","url":"https://github.com/triggerdotdev/trigger.dev/commit/878c15811aca8339a751aa0c2211012db7a47ce5"},{"type":"PACKAGE","url":"https://github.com/triggerdotdev/trigger.dev"},{"type":"WEB","url":"https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.9"}],"affected":[{"package":{"name":"trigger.dev","ecosystem":"npm","purl":"pkg:npm/trigger.dev"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.5.9"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 4.5.8","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-fj2x-mqqp-3v2w/GHSA-fj2x-mqqp-3v2w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}