๐Ÿ” CVE Alert

CVE-2026-62945

MEDIUM 4.3

TREK: Cross-trip reservation title disclosure via file links

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled reservation_id, place_id, and assignment_id values without using findForeignLinkTarget() to verify that the referenced object belongs to the file's trip. An authenticated user with file-edit permission on any accessible trip can submit a foreign reservation identifier through POST /api/trips/:tripId/files/:id/link, POST /api/trips/:tripId/files, or PUT /api/trips/:tripId/files/:id. Subsequent reads through FILE_SELECT or getFileLinks() join the foreign reservation and return reservation_title, disclosing reservation existence and titles across private trip boundaries. This issue is fixed in version 3.1.3.

CWE CWE-639
Vendor mauriceboe
Product trek
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for mauriceboe trek

Be the first to know when new medium vulnerabilities affecting mauriceboe trek are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

mauriceboe / TREK
< 3.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/liketrek/TREK/security/advisories/GHSA-r4cp-666p-8f69 github.com: https://github.com/liketrek/TREK/pull/1324 github.com: https://github.com/liketrek/TREK/commit/03cdb4d27689922460ba87085d04b426d4d40d26 github.com: https://github.com/liketrek/TREK/releases/tag/v3.1.3