trigger-dev

Direct Vulnerabilities

Known vulnerabilities in the trigger-dev package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Resource Exhaustion

<4.5.10-r0
  • L
Uncaught Exception

<4.5.8-r0
  • L
Interpretation Conflict

<4.5.8-r0
  • L
Incorrect Type Conversion or Cast

<4.5.8-r0
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

<4.5.8-r0
  • M
Cross-site Scripting (XSS)

<4.5.8-r0
  • H
Excessive Iteration

<4.5.0-r0
  • M
Algorithmic Complexity

<4.5.0-r0
  • M
Information Exposure

<4.5.0-r0
  • M
Open Redirect

<4.5.0-r0
  • M
Allocation of Resources Without Limits or Throttling

<4.5.0-r0
  • M
Information Exposure Through Caching

<4.5.0-r0
  • M
Server-Side Request Forgery (SSRF)

<4.5.0-r0
  • M
Improper Encoding or Escaping of Output

<4.5.0-r0
  • L
Uncaught Exception

<4.5.4-r0
  • L
GHSA-f88m-g3jw-g9cj

<4.5.0-r0
  • L
Allocation of Resources Without Limits or Throttling

<4.5.8-r0
  • H
OS Command Injection

<4.5.0-r0
  • L
GHSA-wqvq-jvpq-h66f

<4.5.4-r0
  • L
CVE-2026-9678

<4.5.4-r0
  • L
CVE-2026-39410

<4.5.4-r0
  • M
Incorrect Regular Expression

<4.5.4-r0
  • L
HTTP Request Smuggling

<4.5.4-r0
  • H
Directory Traversal

<4.5.4-r0
  • L
Incorrect Regular Expression

<4.5.4-r0
  • L
Arbitrary Code Injection

<4.5.4-r0
  • L
Inappropriate Comment Style

<4.5.4-r0
  • L
GHSA-gq3j-xvxp-8hrf

<4.5.4-r0
  • L
Cleartext Transmission of Sensitive Information

<4.5.4-r0
  • L
GHSA-268h-hp4c-crq3

<4.5.4-r0
  • M
Improper Authorization

<4.5.4-r0
  • L
Insufficient Verification of Data Authenticity

<4.5.4-r0
  • L
Improper Encoding or Escaping of Output

<4.5.4-r0
  • M
Cross-site Scripting (XSS)

<4.5.4-r0
  • L
Resource Exhaustion

<4.5.4-r0
  • M
Incorrect Behavior Order: Validate Before Canonicalize

<4.5.4-r0
  • L
CVE-2026-56761

<4.5.4-r0
  • M
HTTP Response Splitting

<4.5.4-r0
  • M
Information Exposure

<4.5.4-r0
  • M
Arbitrary Code Injection

<4.5.4-r0
  • L
Use of Less Trusted Source

<4.5.4-r0
  • H
Use of Uninitialized Resource

<4.5.4-r0
  • L
GHSA-26pp-8wgv-hjvm

<4.5.4-r0
  • L
Information Exposure Through Caching

<4.5.4-r0
  • L
Resource Exhaustion

<4.5.4-r0
  • L
Arbitrary Code Injection

<4.5.4-r0
  • L
Directory Traversal

<4.5.4-r0
  • L
GHSA-v8w9-8mx6-g223

<4.5.4-r0
  • L
Information Exposure

<4.5.4-r0
  • L
Cross-site Request Forgery (CSRF)

<4.5.4-r0
  • L
Improper Validation of Specified Quantity in Input

<4.5.4-r0
  • L
GHSA-r7g4-qg5f-qqm2

<4.5.4-r0
  • L
GHSA-q7jf-gf43-6x6p

<4.5.4-r0
  • L
Uncaught Exception

<4.5.4-r0
  • M
Directory Traversal

<4.5.4-r0
  • L
Information Exposure Through Caching

<4.5.4-r0
  • L
CVE-2024-55565

<4.5.2-r0
  • L
CVE-2024-28863

<4.5.2-r0
  • H
Inefficient Regular Expression Complexity

<4.5.2-r0
  • M
CVE-2021-23368

<4.5.2-r0
  • M
Arbitrary Code Injection

<4.5.2-r0
  • L
Cross-site Scripting (XSS)

<4.5.2-r0
  • M
Server-Side Request Forgery (SSRF)

<4.5.2-r0
  • L
Inefficient Regular Expression Complexity

<4.5.2-r0
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<4.5.2-r0
  • C
CVE-2026-1525

*
  • L
Information Exposure

<4.5.0-r0
  • H
Server-Side Request Forgery (SSRF)

<4.5.0-r0
  • M
Directory Traversal

<4.5.8-r0
  • L
Inefficient Regular Expression Complexity

*
  • L
CVE-2026-8723

<4.5.0-r0
  • L
CVE-2026-4926

*
  • L
GHSA-h25m-26qc-wcjf

<4.5.0-r0
  • L
Uncaught Exception

*
  • H
Inefficient Regular Expression Complexity

*
  • L
CVE-2025-9910

<4.5.0-r0
  • L
Authentication Bypass

<4.5.0-r0
  • M
Directory Traversal

<4.5.8-r0
  • L
Information Exposure

<4.5.0-r0
  • L
CVE-2026-3635

<4.5.0-r0
  • M
CVE-2025-48068

<4.5.0-r0
  • L
CVE-2026-2229

*
  • L
Improper Handling of Unicode Encoding

<4.5.0-r0
  • L
Allocation of Resources Without Limits or Throttling

<4.5.8-r0
  • L
Race Condition

<4.5.0-r0
  • M
Improper Verification of Cryptographic Signature

<4.5.4-r0
  • L
Information Exposure Through Caching

<4.5.0-r0
  • L
Inefficient Regular Expression Complexity

*
  • L
CVE-2025-22869

*
  • L
GHSA-6v7q-wjvx-w8wg

<4.5.0-r0
  • H
Authentication Bypass

*
  • L
Resource Exhaustion

<4.5.0-r0
  • L
Resource Exhaustion

<4.5.0-r0
  • L
Deserialization of Untrusted Data

<4.5.0-r0
  • L
Interpretation Conflict

<4.5.0-r0
  • L
GHSA-8h8q-6873-q5fj

<4.5.0-r0
  • H
Resource Exhaustion

<4.5.0-r0
  • L
Race Condition

*
  • H
CVE-2026-6734

<4.5.4-r0
  • L
Improper Certificate Validation

*
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • H
Directory Traversal

<4.5.8-r0
  • L
Arbitrary Code Injection

<4.5.0-r0
  • L
Reachable Assertion

*
  • L
Improper Authorization

<4.5.0-r0
  • L
Uncontrolled Recursion

<4.5.0-r0
  • L
GHSA-p6gq-j5cr-w38f

<4.5.4-r0
  • L
Allocation of Resources Without Limits or Throttling

<4.5.0-r0
  • L
CVE-2024-37890

<4.5.4-r0
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<4.5.0-r0
  • H
CVE-2025-59471

<4.5.0-r0
  • L
Resource Exhaustion

<4.5.0-r0
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<4.5.0-r0
  • M
Link Following

<4.5.0-r0
  • L
Resource Exhaustion

<4.5.0-r0
  • L
Resource Exhaustion

<4.5.0-r0
  • L
Cross-site Request Forgery (CSRF)

<4.5.0-r0
  • M
Cross-site Scripting (XSS)

<4.5.0-r0
  • L
Algorithmic Complexity

*
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<4.5.0-r0
  • H
CVE-2024-34351

<4.5.0-r0
  • L
Uncontrolled Recursion

<4.5.0-r0
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
GHSA-5j59-xgg2-r9c4

<4.5.0-r0
  • C
Improper Handling of URL Encoding (Hex Encoding)

<4.5.4-r0
  • L
Algorithmic Complexity

*
  • L
Incorrect Authorization

*
  • H
Improper Certificate Validation

*
  • L
GHSA-q4gf-8mx6-v5v3

<4.5.0-r0
  • H
Uncontrolled Recursion

<4.5.0-r0
  • L
Improper Verification of Cryptographic Signature

*
  • L
OS Command Injection

<4.5.0-r0
  • L
GHSA-w37m-7fhw-fmv9

<4.5.0-r0
  • M
Directory Traversal

<4.5.8-r0
  • L
Interpretation Conflict

<4.5.0-r0
  • H
Resource Exhaustion

*
  • H
Arbitrary Code Injection

<4.5.0-r0
  • L
Improper Handling of Exceptional Conditions

<4.5.0-r0
  • L
Resource Exhaustion

<4.5.4-r0
  • H
Inefficient Regular Expression Complexity

<4.5.0-r0
  • L
Allocation of Resources Without Limits or Throttling

<4.5.0-r0
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<4.5.0-r0
  • L
CVE-2026-33806

<4.5.0-r0
  • L
Improper Input Validation

<4.5.0-r0
  • C
Directory Traversal

*
  • L
OS Command Injection

*
  • L
Directory Traversal

*
  • L
CVE-2026-1526

*
  • L
CVE-2026-32280

*
  • L
Allocation of Resources Without Limits or Throttling

<4.5.0-r0
  • L
Server-Side Request Forgery (SSRF)

<4.5.0-r0
  • L
Uncaught Exception

*
  • L
XML Injection

<4.5.0-r0
  • M
Improper Verification of Cryptographic Signature

<4.5.4-r0
  • M
Open Redirect

<4.5.0-r0
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<4.5.0-r0
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
CVE-2026-9697

<4.5.4-r0
  • L
Direct Request ('Forced Browsing')

*
  • L
Cross-site Scripting (XSS)

<4.5.0-r0
  • H
Information Exposure

<4.5.0-r0
  • L
Improper Input Validation

<4.5.0-r0
  • L
CVE-2026-12143

<4.5.4-r0
  • L
Overly Permissive Cross-domain Whitelist

<4.5.4-r0
  • L
CVE-2026-6322

<4.5.0-r0
  • L
Directory Traversal

<4.5.8-r0
  • L
CVE-2025-1302

<4.5.2-r0
  • L
Improper Certificate Validation

*
  • H
Exposure of Resource to Wrong Sphere

*
  • L
CVE-2025-22868

*
  • L
Arbitrary Code Injection

<4.5.0-r0
  • L
Allocation of Resources Without Limits or Throttling

*
  • H
Symlink Following

*
  • M
HTTP Request Smuggling

<4.5.0-r0
  • L
Race Condition

*
  • L
GHSA-mwv6-3258-q52c

<4.5.0-r0
  • L
XML Injection

<4.5.0-r0
  • M
Cross-site Scripting (XSS)

*
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<4.5.0-r0
  • H
Directory Traversal

<4.5.0-r0
  • H
Incorrect Execution-Assigned Permissions

*
  • M
Cross-site Scripting (XSS)

<4.5.0-r0
  • L
CVE-2026-6321

<4.5.0-r0
  • M
Cross-site Scripting (XSS)

<4.5.0-r0
  • L
Cross-site Scripting (XSS)

<4.5.0-r0
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Allocation of Resources Without Limits or Throttling

<4.5.0-r0
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

<4.5.0-r0
  • H
Resource Exhaustion

<4.5.0-r0
  • H
CVE-2026-2391

<4.5.0-r0
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<4.5.0-r0
  • L
Improper Authorization

<4.5.4-r0
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Resource Exhaustion

<4.5.0-r0
  • M
CVE-2025-48985

<4.5.0-r0
  • L
Reversible One-Way Hash

<4.5.0-r0
  • H
Uncontrolled Recursion

<4.5.0-r0
  • L
GHSA-5c6j-r48x-rmvq

<4.5.0-r0
  • L
Incorrect Authorization

<4.5.0-r0
  • L
Authentication Bypass

<4.5.0-r0
  • C
Use of a Broken or Risky Cryptographic Algorithm

*
  • L
CVE-2024-41110

*
  • L
Out-of-Bounds

*
  • L
Missing Authorization

*
  • L
Deserialization of Untrusted Data

*
  • L
GHSA-9qr9-h5gf-34mp

<4.5.0-r0
  • L
Improper Authorization

*
  • L
CVE-2026-39821

*
  • C
CVE-2025-68121

*
  • L
Missing Authorization

*
  • L
Authorization Bypass Through User-Controlled Key

<4.5.0-r0
  • L
Improper Certificate Validation

*
  • C
Directory Traversal

<4.5.0-r0
  • L
CVE-2026-9277

<4.5.0-r0
  • C
CVE-2026-27143

*
  • L
CVE-2026-46595

*
  • L
Integer Overflow or Wraparound

*
  • L
CVE-2024-21534

<4.5.2-r0
  • L
CVE-2023-45288

*
  • H
Information Exposure

*
  • L
Incorrect Authorization

<4.5.0-r0
  • H
CVE-2025-31125

*