Description
A vulnerability in the Inngest TypeScript SDK versions 3.22.0 through 3.53.1 allows unauthenticated remote attackers to exfiltrate environment variables from the host process via the serve() HTTP handler.
The serve() handler implements GET, POST, and PUT methods.
Recommendation
Update the inngest package to the latest compatible version. Followings are version details:
- Affected version(s): >= 3.22.0, < 3.54.0
- Patched version(s): 3.54.0
References
Could your website be exposed too?
SmartScanner can check your website for Inngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methods and gives you actionable findings to investigate.
Start a free scanRelated Issues
- CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function - CVE-2026-26861
- @rvf/set-get has a prototype pollution issue that's reachable via @rvf/core preprocessFormData (HTTP form data) - CVE-2026-44483
- OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header - CVE-2026-59892
- DbGate has cross site scripting via the SVG Icon String Handler component - CVE-2026-6216


