THREAT OPS › Threat News › [GHSA] GHSA-p28v-f755-9qrg (high) — Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
[GHSA] GHSA-p28v-f755-9qrg (high) — Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
GHSA-p28v-f755-9qrg Severity: high CVE: CVE-2026-73654
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
## Summary
The run-metadata update endpoint `PUT /api/v1/runs/:runId/metadata` applies client-supplied "operations" by passing the **attacker-controlled `operation.key`** straight into `new JSONHeroPath(operation.key).set(newMetadata, value)` (`pack
Indicators of compromise
- CVE-2026-73654cve
- ghcr.iodomain
Original source: https://github.com/advisories/GHSA-p28v-f755-9qrg