Home / Companies / Inngest / Blog / Post Details
Content Deep Dive

Security vulnerability in v3 TypeScript SDK

Blog post from Inngest

Post Details
Company
Date Published
Author
Dan Farrelly
Word Count
1,672
Company Posts That Month
9
Language
-
Hacker News Points
-
Post removed?
No
Summary

A critical security vulnerability was discovered in the Inngest TypeScript SDK, affecting versions between 3.22 and 3.53.1, which potentially allowed the exposure of environment variables through the application's serve endpoint. This vulnerability was responsibly disclosed by a customer on April 20, 2026, and the Inngest team promptly addressed the issue by releasing version 3.54.0, which contains a fix. Users with affected versions are advised to upgrade to v3.54.0 or later and rotate environment variables and Inngest keys. The vulnerability primarily impacted applications configured to handle PATCH, OPTIONS, or DELETE HTTP methods, except for those using specific frameworks like Next.js App Router. In response, Inngest has implemented further security measures, collaborated with partners for mitigation, and plans to introduce additional features such as audit trails and a bug bounty program to enhance future security. The discovery is credited to independent security researcher Ben Hylak, and Inngest has reiterated its commitment to user security while expressing gratitude for partner support.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 1 1,821 338 111 +22%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.