Trigger.dev versions prior to 4.5.2 contain a vulnerability where environment membership is not validated during run replay operations. Authenticated attackers can exploit this flaw to inject task runs into arbitrary environments belonging to other organizations or projects. This allows attackers to consume victim resources and pollute run history without authorization. The vulnerability affects the multi-tenant isolation model of the platform. A fix was released in version 4.5.2 with a corresponding commit and security advisory. The issue was tracked and disclosed via GitHub issues and a security advisory under GHSA-qxpp-qjg8-x4jv. VulnCheck also published an advisory detailing the unauthorized environment access vector. Users are strongly advised to upgrade to version 4.5.2 or later immediately.