Vulnerability GHSA-fj2x-mqqp-3v2w
Summary
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values
Details
Affected version: trigger.dev 4.5.3 (4.5.6 was advertised by the CLI but was not tested).
A staging dry-run executed with trigger.dev deploy --env staging --dry-run --log-level debug. The debug output logged the complete build-worker options object. Its envVars property contained unredacted values for every resolved staging variable, including database connection strings and service credentials. The non-debug environment listing correctly hides values, so users can reasonably expect deployment logs not to print secrets.
Impact: anyone with access to a developer terminal transcript, CI debug log, captured agent/tool output, or support bundle can recover deployment secrets even though no deployment occurs.
Reproduction:
- Configure a Trigger.dev project with a secret environment variable.
- Run the command above with an authenticated profile.
- Inspect the
Starting buildWorkerdebug record. options.envVarscontains the plaintext value.
No real credential is included in this report. The observed customer credentials are being rotated separately.
Suggested remediation: never serialize envVars values in debug output; log names only or replace every value with a fixed marker. Add regression coverage for deploy, dry-run, and debug logging, and review adjacent debug records for resolved secrets.
Related Vulnerabilities
Other vulnerabilities affecting the same packages