THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p28v-f755-9qrg (high) — Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS

[GHSA] GHSA-p28v-f755-9qrg (high) — Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS

highgithub_advisoriesPublished 2026-08-13

GHSA-p28v-f755-9qrg Severity: high CVE: CVE-2026-73654

Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS

## Summary

The run-metadata update endpoint `PUT /api/v1/runs/:runId/metadata` applies client-supplied "operations" by passing the **attacker-controlled `operation.key`** straight into `new JSONHeroPath(operation.key).set(newMetadata, value)` (`pack

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p28v-f755-9qrg