CVE-2026-73654 | triggerdotdev trigger.dev up to 4.5.5 Run Metadata operations.ts JSONHeroPath.set operation.key denial of service
A vulnerability has been found in triggerdotdev trigger.dev up to 4.5.5 and classified as problematic. This impacts the function JSONHeroPath.set of the file packages/core/src/v3/runMetadata/operations.ts of the component Run Metadata. Performing a manipulation of the argument operation.key results in denial of service.
This vulnerability is known as CVE-2026-73654. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.VulDB Recent EntriesRead More