SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85650

MEDIUM · CVSS 5.4 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Trigger.dev versions prior to 4.5.2 are vulnerable to a server-side request forgery (SSRF) flaw that allows authenticated users to create alert channels with unvalidated URLs, potentially targeting internal services and metadata endpoints. This could enable attackers to exploit restricted resources by issuing unauthorized POST requests. Organizations using this software should prioritize remediation to mitigate the risk of unauthorized access to sensitive internal systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85650
Severity
MEDIUM
CVSS
5.4
EPSS
0.31%

Original NVD Description

Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert channels with URLs targeting internal services and metadata endpoints, allowing the server to issue POST requests to restricted resources.