<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T00:24:27.742327+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352520</id>
    <title>EUVD-2026-352520</title>
    <updated>2026-10-08T00:24:27.744579+00:00</updated>
    <content>EUVD-2026-352520</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352520"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73654</id>
    <title>fkie_cve-2026-73654</title>
    <updated>2026-10-08T00:24:27.744612+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the PUT /api/v1/runs/:runId/metadata endpoint passes attacker-controlled operation.key values to new JSONHeroPath(operation.key).set(newMetadata, value) in packages/core/src/v3/runMetadata/operations.ts without rejecting dangerous constructor and prototype path segments. A caller with a normal environment API key can pollute Object.prototype in the shared webapp process, corrupting Prisma queries and Prometheus labels, breaking other tenants' worker authentication, and causing a process-wide denial of service. This issue is fixed in version 4.5.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73654"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p28v-f755-9qrg</id>
    <title>GHSA-p28v-f755-9qrg — Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS</title>
    <updated>2026-10-08T00:24:27.744646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @trigger.dev/core</p>
<p>## Summary</p>
<p>The run-metadata update endpoint `PUT /api/v1/runs/:runId/metadata` applies client-supplied
"operations" by passing the **attacker-controlled `operation.key`** straight into
`new JSONHeroPath(operation.key).set(newMetadata, value)`
(`packages/core/src/v3/runMetadata/operations.ts:22-23`), with **no prototype-pollution guard**
(`@jsonhero/path@^1.0.21` does not reject `__proto__`/`constructor`/`prototype`).</p>
<p>A request with `key: "$.__proto__.polluted"` sets **`Object.prototype.polluted`** in the webapp
process. Because every plain object then inherits that property, it corrupts unrelated code
**process-wide and across tenants** — including Prisma query building and the Prometheus metrics
client — causing query failures, **broken authentication for other tenants' workers**, and an
`uncaughtException` (denial of service). Only a normal, low-privilege environment API key is
required (one request).</p>
<p>## Severity</p>
<p>A single request from any holder of a normal environment API key contaminates `Object.prototype`
in the shared webapp process, breaking other tenants' workers (scope change) and degrading/
crashing the process (high availability impact). Prototype pollution is also a primitive for
further gadget chains (integrity/confidentiality).</p>
<p>## Affected versions</p>
<p>- **Introduced** in commit `34f8bd588` ("Add ability to update parent and root run metadata from
  children", PR #1563, 2025-01-08) — the `JSONHeroPath(operation.key).set()` sink is present from
  the first com…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p28v-f755-9qrg"/>
  </entry>
</feed>
