Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54505— TREK: Stored cross-user HTML injection via trip title in the Journey suggestion banner

Quick assessment

Affected
mauriceboe TREK
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

TREK 是一款协作式旅行规划工具。在 3.1.0 版本之前,当启用“行程”(Journey)插件时,TREK 会通过 将未转义的 值插值到 中,并在 中使用 渲染该结果。 行程所有者可以在符合条件的行程标题中存储 HTML 内容,而 接口通过 方法将该标题返回给访问已认证行程页面的协作者。这些恶意标记会在协作者的会话中被作为实时 DOM 插入,从而导致内容伪装(content spoofing)和 UI 重定向(UI redress)攻击。不过,由于默认的内容安全策略(CSP)禁止内联处理程序和脚本执行,此类攻击

CVSS 2.0 · Low EPSS 0.43% · P35

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise

Affected Version Matrix 1

VendorProduct Version RangeStatus
mauriceboe TREK < 3.1.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54505

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
TREK: Stored cross-user HTML injection via trip title in the Journey suggestion banner
Source: CVE Program / CVE List V5
Vulnerability Description
TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unescaped activeSuggestion.title value into journey.frontpage.suggestionText through client/src/i18n/TranslationContext.tsx and renders the result with dangerouslySetInnerHTML in client/src/pages/JourneyPage.tsx. A trip owner can store HTML in a qualifying trip title, and GET /api/journeys/suggestions returns that title through getSuggestions(userId) to a collaborator who opens the authenticated Journey page. The markup is inserted as live DOM in the collaborator's session, enabling content spoofing and UI redress, although the default Content Security Policy blocks inline handlers and script execution. This issue is fixed in version 3.1.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
mauriceboe TREK < 3.1.0 -

II. Public POCs for CVE-2026-54505

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54505

登录查看更多情报信息。

Patches & Fixes for CVE-2026-54505 (1)

Vendor Advisories for CVE-2026-54505 (1)

Other References for CVE-2026-54505 (1)

Same Patch Batch · mauriceboe · 2026-08-20 · 4 CVEs total

CVE-2026-54509 6.5 MEDIUM TREK IDOR: any authenticated user can read another user's journey share token (full journe
CVE-2026-54508 5.3 MEDIUM TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps U
CVE-2026-62945 4.3 MEDIUM TREK: Cross-trip reservation title disclosure via file links

IV. Related Vulnerabilities

V. Comments for CVE-2026-54505

No comments yet


Leave a comment