What is CVE-2026-73659?
In Trigger.dev versions 4.4.2 through 4.5.0, a vulnerability exists in the packet presign routes where a caller-controlled filename is passed to `generatePresignedUrl` via `resolveStoreProtocolForPacketPresign`. This could allow unauthorized operations through the presigned URL generation. Affected users should immediately update to the latest patched version.
Azərbaycanca: Trigger.dev platformasında 4.4.2-4.5.0 versiyalar arasında `packet presign` marşrutlarında istifadəçi tərəfindən idarə olunan fayl adı səbəbindən təhlükəsizlik boşluğu mövcuddur. Bu, `generatePresignedUrl` funksiyası vasitəsilə icazəsiz əməliyyatlara yol aça bilər. Təsirə məruz qalan versiyaları istifadə edən istifadəçilər dərhal ən son təhlükəsizlik yeniləməsinə keçməlidirlər.
FAQ2
Which versions of Trigger.dev are affected by CVE-2026-73659?
This vulnerability affects Trigger.dev versions 4.4.2 through 4.5.0.
What is the root cause of CVE-2026-73659?
The vulnerability is caused by a caller-controlled filename passed to the `generatePresignedUrl` function in the packet presign routes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.