Skip to content
Brief Security & Trust ·

Trigger.dev self-hosted setups with default secrets can be taken over

A GitHub advisory says self-hosted trigger.dev v4 installs that kept the example secrets let outsiders forge a login for any email address, and describes a chain to full compromise.

In brief
  • GitHub's advisory database says self-hosted trigger.dev v4 installs that kept the example secrets can be taken over without a login.
  • The advisory names release v4.5.6 but does not say what it changes, rate the severity or report attacks.

The GitHub Advisory Database said on 2 October 2026 that self-hosted trigger.dev v4 installs can be taken over. It covers setups built from the provided Docker Compose files that kept the default secrets in hosting/docker/.env.example. The advisory describes a chain of steps, needing no login, that ends in complete compromise of the infrastructure.

Login links are encrypted tokens, and their key, MAGIC_LINK_SECRET, sits in that example file. The advisory says anyone with it can forge a link for any email address. A library check for that is off by default, and trigger.dev never turned it on. New accounts are made automatically unless WHITELISTED_EMAILS is set. The advisory lists tenant data, API keys and stored secrets as exposed, plus backdoored images in the registry. It points to release v4.5.6 but does not say what that changes. It gives no severity rating, no fix steps and no reports of attacks.

Our reading, not the advisory's: example secrets that work as defaults give every unchanged install the same keys. If an attacker already read stored secrets, new keys will not undo that. Changing ENCRYPTION_KEY on a live install needs care, since it protects stored data. Leaders can ask who owns self-hosted tools, how to find instances on example values, and what each would expose.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: GitHub Advisory Database.