Security vulnerability in v3 TypeScript SDK
Blog post from Inngest
A critical security vulnerability was discovered in the Inngest TypeScript SDK, affecting versions between 3.22 and 3.53.1, which potentially allowed the exposure of environment variables through the application's serve endpoint. This vulnerability was responsibly disclosed by a customer on April 20, 2026, and the Inngest team promptly addressed the issue by releasing version 3.54.0, which contains a fix. Users with affected versions are advised to upgrade to v3.54.0 or later and rotate environment variables and Inngest keys. The vulnerability primarily impacted applications configured to handle PATCH, OPTIONS, or DELETE HTTP methods, except for those using specific frameworks like Next.js App Router. In response, Inngest has implemented further security measures, collaborated with partners for mitigation, and plans to introduce additional features such as audit trails and a bug bounty program to enhance future security. The discovery is credited to independent security researcher Ben Hylak, and Inngest has reiterated its commitment to user security while expressing gratitude for partner support.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 1 | 1,821 | 338 | 111 | +22% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.