A vulnerability was found in triggerdotdev Trigger.dev up to 4.5.0-rc.4. It has been classified as critical. Affected is the function
Aws4FetchClient.buildUrl/Aws4FetchClient.presign of the file apps/webapp/app/v3/objectStoreClient.server.ts of the component Path Normalization. This manipulation of the argument params causes improper input validation.
This vulnerability is registered as CVE-2026-73658. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.