What is CVE-2026-73657?
CVE-2026-73657 is a vulnerability in the Trigger.dev platform. Between versions 4.4.2 and 4.5.0-rc.4, the `POST /api/v1/runs/:runParam/replay` endpoint uses `prisma.taskRun.findUnique` without filtering by the full run identifier (`runt`). This could allow unauthorized replay of operations. Users should update to the latest stable version.
Azərbaycanca: CVE-2026-73657 Trigger.dev platformunda aşkar edilmiş boşluqdur. 4.4.2 ilə 4.5.0-rc.4 versiyaları arasında `/api/v1/runs/:runParam/replay` endpointində `runParam` parametri `prisma.taskRun.findUnique` ilə filtrlənərkən tam işləmə identifikatoru (`runt`) olmadan sorğulanır. Bu, icazəsiz əməliyyat replayinə imkan yarada bilər. İstifadəçilərə ən son stabil versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which versions of the Trigger.dev platform are affected by CVE-2026-73657?
Versions between 4.4.2 and 4.5.0-rc.4 are affected.
What is the root cause of CVE-2026-73657 in the `/api/v1/runs/:runParam/replay` endpoint?
The lack of filtering by the full run identifier (`runt`).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.