Listen to this Post
Trigger.dev is an open-source platform for background jobs and durable workflows. The vulnerability resides in the Trigger.dev CLI version 4.5.3. When a user executes a staging dry-run with the command trigger.dev deploy --env staging --dry-run --log-level debug, the CLI outputs the complete build-worker options object. This object includes the `envVars` property, which contains unredacted values for all resolved staging variables. These variables include database connection strings and service credentials. The non-debug environment listing correctly hides these values, leading users to expect that deployment logs will not print secrets. However, the debug log inadvertently exposes them. The issue is classified as CWE-532 (Insertion of Sensitive Information into Log File). The impact is that anyone with access to a developer terminal transcript, CI debug log, captured agent/tool output, or support bundle can recover deployment secrets even though no deployment occurs. The vulnerability was discovered and reported, and a fix has been implemented in version 4.5.9. The advisory was published on 2026-10-02. The severity is rated as Medium. The root cause is the serialization of environment variables in debug output. The reproduction steps are: configure a Trigger.dev project with a secret environment variable, run the command with an authenticated profile, inspect the “Starting buildWorker” debug record, and observe that `options.envVars` contains plaintext values. The suggested remediation is to never serialize `envVars` values in debug output; log names only or replace every value with a fixed marker. Additionally, add regression coverage for deploy, dry-run, and debug logging, and review adjacent debug records for resolved secrets. This vulnerability highlights the importance of redacting sensitive information in debug logs. The CVE ID is not assigned; the advisory identifier is GHSA-FJ2X-MQQP-3V2W.
DailyCVE Form:
Platform: Trigger.dev CLI
Version: 4.5.3
Vulnerability: Env secret leakage
Severity: Medium
date: 2026-10-02
Prediction: 2026-08-01
What Undercode Say:
trigger.dev deploy --env staging --dry-run --log-level debug
[bash] Starting buildWorker
options.envVars = {
DATABASE_URL: "postgres://user:pass@host:5432/db",
API_KEY: "secret123"
}
grep -r "envVars" ./logs/
Exploit: (Educational Purposes!)
- Configure a Trigger.dev project with a secret environment variable.
- Run `trigger.dev deploy –env staging –dry-run –log-level debug` with an authenticated profile.
3. Inspect the `Starting buildWorker` debug record.
4. `options.envVars` contains the plaintext value.
Protection:
- Never use `–log-level debug` in production or CI environments.
- Redact `envVars` values in debug output; log names only.
- Replace every value with a fixed marker.
- Add regression coverage for deploy, dry-run, and debug logging.
- Review adjacent debug records for resolved secrets.
Impact:
- Exposure of database credentials, API keys, and service secrets.
- Unauthorized access to staging or production environments.
- Risk of data breaches and lateral movement.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

