TREK 是一款协作式旅行规划工具。在 3.3.0 版本之前, 中注册的 工具在使用作用域受限的 OAuth MCP 令牌时,并未要求具备 权限,但仍会返回核心的行程摘要数据,无论令牌的委托作用域如何。即使令牌仅被授予了无关的能力(例如 ),仍能获取该令牌所属用户可访问的所有行程的元数据、成员邮箱地址(来自 )、行程每日安排以及住宿信息。虽然跨用户行程的授权控制仍然有效,但缺失的作用域检查破坏了经用户同意的最小权限边界,导致未获授权读取的 MCP 客户端也能访问行程内容和第三方联系信息。此问题已在 3.3.0 版本
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mauriceboe | TREK | < 3.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mauriceboe | TREK | < 3.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77294 | 8.1 HIGH | TREK: Server-Side Request Forgery via User-Configurable LLM Base URL |
| CVE-2026-77293 | 7.1 HIGH | TREK: Cross-user note-file deletion (IDOR / Broken Access Control) |
| CVE-2026-77320 | 5.3 MEDIUM | TREK: Public trip share link ignores the `share_map` permission server-side (client-enforc |
No comments yet