{"id":"GHSA-4672-hwv6-gq62","summary":"Trigger.dev: Cross-environment deployment cancel","details":"### Summary\n\nTrigger.dev isolates each project into multiple **environments** (`dev`, `staging`, `prod`, and per-PR `preview` branches), each with its **own secret API key** — the environment is a trust boundary (a `dev`/preview/CI key is lower-trust than a `prod` key). Most API routes enforce this by scoping resource lookups to the authenticated key's environment (`where: { friendlyId, runtimeEnvironmentId: auth.environment.id }`).\n\nThe deployment **cancel** path does not. `DeploymentService.getDeployment()` scopes the lookup by **`projectId` only** — never `environmentId` — so a secret key for *any* environment in a project can cancel a deployment belonging to *any other* environment of the same project, including **production**. The deployment **GET** route, by contrast, *is* env-scoped — so the same key that is **404'd when trying to read** a prod deployment can nonetheless **cancel** it. That asymmetry is the bug.\n\n### Affected\n\n`apps/webapp`, HEAD `5d99457` (current `main`). Affects self-hosted and cloud.\n\n### Root cause\n\n`apps/webapp/app/routes/api.v1.deployments.$deploymentId.cancel.ts` authenticates to an environment and calls `deploymentService.cancelDeployment(authenticatedEnv, deploymentId, ...)`.\n\n`apps/webapp/app/v3/services/deployment.server.ts`:\n```ts\npublic cancelDeployment(authenticatedEnv: Pick\u003cAuthenticatedEnvironment,\"projectId\"\u003e, friendlyId, ...) {\n  return this.getDeployment(authenticatedEnv.projectId, friendlyId)   // projectId only\n    .andThen(validateDeployment)                                      // rejects only FINAL statuses\n    .andThen(cancelDeployment);                                       // updateMany -\u003e status CANCELED\n}\nprivate getDeployment(projectId: string, friendlyId: string) {\n  return this._prisma.workerDeployment.findFirst({\n    where: { friendlyId, projectId },        // \u003c-- NO environmentId filter\n  });\n}\n```\n\n`cancelDeployment` accepts `authenticatedEnv` but its type is literally `Pick\u003cAuthenticatedEnvironment,\"projectId\"\u003e` — it discards the environment identity. `validateDeployment` blocks only `FINAL_DEPLOYMENT_STATUSES`, so any in-progress deployment (`PENDING`/`INSTALLING`/`BUILDING`/`DEPLOYING`) is cancellable.\n\n**Contrast — the correctly env-scoped sibling** `api.v1.deployments.$deploymentId.ts` (GET):\n```ts\nconst deployment = await prisma.workerDeployment.findFirst({\n  where: { friendlyId: deploymentId, environmentId: authenticatedEnv.id },   // env-scoped\n});\n```\nReads are env-scoped; the cancel mutation is not. The same `getDeployment(authenticatedEnv.projectId, …)` helper also backs the deployment *progress* methods (`deployment.server.ts:172,329`), so the projectId-only scope is a small class.\n\n### Runtime PoC (proven on the self-host stack)\n\nSeeded one project with a `prod` env (key `tr_prod_…`) and a `dev` env (key `tr_dev_…`) and one `WorkerDeployment` (`deployment_pocvictim`, status `DEPLOYING`) in the **prod** env. As the **dev** key:\n\n```\nstatus BEFORE                                                  : DEPLOYING\nGET  /api/v1/deployments/deployment_pocvictim   (dev key)      -\u003e 404   (env-scoped read DENIES it)\nPOST /api/v1/deployments/deployment_pocvictim/cancel (dev key) -\u003e 204\nstatus AFTER                                                   : CANCELED   (prod deploy canceled by the dev key)\nCONTROL: same cancel with a DIFFERENT project's key            -\u003e 404   (projectId scope blocks cross-project)\n```\n\nThe dev key cannot *read* the prod deployment (404) yet *cancels* it (204 → CANCELED); a different project's key is correctly 404'd — so the gap is precisely cross-environment within a project.","modified":"2026-10-02T23:00:17.531579465Z","published":"2026-10-02T22:42:40Z","database_specific":{"github_reviewed_at":"2026-10-02T22:42:40Z","nvd_published_at":null,"cwe_ids":["CWE-639"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-4672-hwv6-gq62"},{"type":"WEB","url":"https://github.com/triggerdotdev/trigger.dev/pull/4316"},{"type":"WEB","url":"https://github.com/triggerdotdev/trigger.dev/commit/6997aeb05e27d2db47f9eda01fdc8a17c81a1ae0"},{"type":"PACKAGE","url":"https://github.com/triggerdotdev/trigger.dev"},{"type":"WEB","url":"https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.6"}],"affected":[{"package":{"name":"trigger.dev","ecosystem":"npm","purl":"pkg:npm/trigger.dev"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.5.6"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 4.5.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-4672-hwv6-gq62/GHSA-4672-hwv6-gq62.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"}]}