TREK 是一款协作式旅行规划工具。在 3.1.3 版本之前,TREK 的文件上传、更新和链接功能允许攻击者传入由攻击者控制的 、 和 值,而未使用 函数来验证所引用的对象是否属于该文件所属的行程。具有对任意可访问行程的文件编辑权限的认证用户,可以通过以下 API 端点提交外部(非属当前行程)预订标识符: 随后,通过 或 进行读取操作时,会将外部预订关联进来,并返回 (预订标题),从而泄露不同私有行程边界下的预订存在性及标题信息。此问题已在 3.1.3 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mauriceboe | TREK | < 3.1.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mauriceboe | TREK | < 3.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54509 | 6.5 MEDIUM | TREK IDOR: any authenticated user can read another user's journey share token (full journe |
| CVE-2026-54508 | 5.3 MEDIUM | TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps U |
| CVE-2026-54505 | 2.0 LOW | TREK: Stored cross-user HTML injection via trip title in the Journey suggestion banner |
No comments yet