TREK 是一款协作式旅行规划工具。在 3.1.0 版本之前,TREK 在 文件中的 和 函数,以及 文件中的 函数中,仅在原生重定向发生前对初始 URL 进行验证。受影响的这些函数会调用 中的 函数,但随后却使用带有 选项的 方法,而非采用通过 DNS 固定(DNS-pinned)机制的安全 路径。因此,攻击者可以通过控制的公开 URL 引导服务器重定向到回环地址(loopback)、RFC 1918 私有网络地址或云元数据地址,且不会在重定向过程中重新进行验证。 已认证为行程成员的用户可以通过列表导入相关路由发
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mauriceboe | TREK | < 3.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mauriceboe | TREK | < 3.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54509 | 6.5 MEDIUM | TREK IDOR: any authenticated user can read another user's journey share token (full journe |
| CVE-2026-62945 | 4.3 MEDIUM | TREK: Cross-trip reservation title disclosure via file links |
| CVE-2026-54505 | 2.0 LOW | TREK: Stored cross-user HTML injection via trip title in the Journey suggestion banner |
No comments yet