CVE-2026-73657 | triggerdotdev trigger.dev prior 4.5.0-rc.4 Replay replayTaskRun.server.ts overrideExistingPayloadPacket runParam access control
A vulnerability was found in triggerdotdev trigger.dev and classified as critical. This impacts the function overrideExistingPayloadPacket of the file apps/webapp/app/v3/services/replayTaskRun.server.ts of the component Replay. The manipulation of the argument runParam results in improper access controls.
This vulnerability is cataloged as CVE-2026-73657. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More