TREK 是一款协作式旅行规划应用。在版本 3.0.0 至 3.1.0 之间, 中的 路由直接返回了 中 的结果,而未验证经身份认证的用户是否有权访问该旅程。任何普通已认证用户都可以通过枚举连续的旅程 ID,获取其他用户旅程的 中的令牌。该令牌允许通过 接口以未认证方式访问共享旅程的条目、字幕、地点、情绪标签、相册照片、照片路径及资产标识符。此问题已在版本 3.1.0 中得到修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mauriceboe | TREK | >= 3.0.0, < 3.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mauriceboe | TREK | >= 3.0.0, < 3.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54508 | 5.3 MEDIUM | TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps U |
| CVE-2026-62945 | 4.3 MEDIUM | TREK: Cross-trip reservation title disclosure via file links |
| CVE-2026-54505 | 2.0 LOW | TREK: Stored cross-user HTML injection via trip title in the Journey suggestion banner |
No comments yet