VulnSea

TREK vulnerabilities

CVEs whose affected-version data names the TREK package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-77293High· 7.1PoC
yesterday

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against the attacker-controlled tripId but deleteNoteFile in server/src/se…

▾ Midnightmauriceboe · TREKvia NVD
CVE-2026-85738Medium· 6.3
yesterday

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not recognize NAT64, 6to4, or Teredo IPv6 transition addresses that encode an IPv4 destination. An authenticated user who c…

▾ Sunlitliketrek · TREKvia NVD
CVE-2026-77321Medium· 4.3
yesterday

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiring trips:read and returns core trip summary data regardless of th…

▾ Sunlitmauriceboe · TREKvia NVD
CVE-2026-77320Medium· 5.3
yesterday

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns days, assignments, dayNotes, and places through GET /api/shared/:token even when the trip owner disables share_map. …

▾ Sunlitmauriceboe · TREKvia NVD
CVE-2026-77294High· 8.1PoC
yesterday

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM_PARSING feature is enabled. Write permission to the target trip …

▾ Midnightmauriceboe · TREKvia NVD
TREK vulnerabilities (CVEs) · VulnSea