CyberRota Analysis
AI-GeneratedTrigger.dev versions prior to 4.5.2 are vulnerable to a server-side request forgery (SSRF) flaw that allows authenticated users to create alert channels with unvalidated URLs, potentially targeting internal services and metadata endpoints. This could enable attackers to exploit restricted resources by issuing unauthorized POST requests. Organizations using this software should prioritize remediation to mitigate the risk of unauthorized access to sensitive internal systems.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert channels with URLs targeting internal services and metadata endpoints, allowing the server to issue POST requests to restricted resources.