TREK 是一款协作式旅行规划工具。在版本 3.3.0 之前, 中的 函数在通过 接口返回数据时,即便行程所有者已禁用“共享地图”(share_map)选项,仍会返回天数安排(days)、任务分配(assignments)、每日备注(dayNotes)以及地点信息(places)。虽然客户端会隐藏地图显示,但公开的 JSON 响应中依然包含完整的行程路线、地点名称、坐标、地址、描述、备注和价格等信息。因此,任何持有有效分享令牌的用户都可以读取到行程所有者明确选择不公开的位置和路线信息。尽管攻击者仍需拥有随机的令牌,
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mauriceboe | TREK | < 3.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mauriceboe | TREK | < 3.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77294 | 8.1 HIGH | TREK: Server-Side Request Forgery via User-Configurable LLM Base URL |
| CVE-2026-77293 | 7.1 HIGH | TREK: Cross-user note-file deletion (IDOR / Broken Access Control) |
| CVE-2026-77321 | 4.3 MEDIUM | TREK MCP trip summary bypasses delegated OAuth read scopes |
No comments yet