TREK 是一款协作式旅行规划工具。在 3.1.0 版本之前,当启用“行程”(Journey)插件时,TREK 会通过 将未转义的 值插值到 中,并在 中使用 渲染该结果。 行程所有者可以在符合条件的行程标题中存储 HTML 内容,而 接口通过 方法将该标题返回给访问已认证行程页面的协作者。这些恶意标记会在协作者的会话中被作为实时 DOM 插入,从而导致内容伪装(content spoofing)和 UI 重定向(UI redress)攻击。不过,由于默认的内容安全策略(CSP)禁止内联处理程序和脚本执行,此类攻击
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mauriceboe | TREK | < 3.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mauriceboe | TREK | < 3.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54509 | 6.5 MEDIUM | TREK IDOR: any authenticated user can read another user's journey share token (full journe |
| CVE-2026-54508 | 5.3 MEDIUM | TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps U |
| CVE-2026-62945 | 4.3 MEDIUM | TREK: Cross-trip reservation title disclosure via file links |
No comments yet