Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-77321— TREK MCP trip summary bypasses delegated OAuth read scopes

Quick assessment

Affected
mauriceboe TREK
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

TREK 是一款协作式旅行规划工具。在 3.3.0 版本之前, 中注册的 工具在使用作用域受限的 OAuth MCP 令牌时,并未要求具备 权限,但仍会返回核心的行程摘要数据,无论令牌的委托作用域如何。即使令牌仅被授予了无关的能力(例如 ),仍能获取该令牌所属用户可访问的所有行程的元数据、成员邮箱地址(来自 )、行程每日安排以及住宿信息。虽然跨用户行程的授权控制仍然有效,但缺失的作用域检查破坏了经用户同意的最小权限边界,导致未获授权读取的 MCP 客户端也能访问行程内容和第三方联系信息。此问题已在 3.3.0 版本

CVSS 4.3 · Medium EPSS 0.20% · P9

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProduct Version RangeStatus
mauriceboe TREK < 3.3.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77321

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
TREK MCP trip summary bypasses delegated OAuth read scopes
Source: CVE Program / CVE List V5
Vulnerability Description
TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiring trips:read and returns core trip summary data regardless of the delegated scopes. A token granted only an unrelated capability, such as weather:read, can receive trip metadata, member email addresses from server/src/services/tripService.ts, itinerary days, and accommodations for every trip accessible to the token's user. Cross-user trip authorization remains enforced, but the missing scope check defeats the consented least-privilege boundary and exposes trip content and third-party contact information to an MCP client that was not authorized to read it. This issue is fixed in version 3.3.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
mauriceboe TREK < 3.3.0 -

II. Public POCs for CVE-2026-77321

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77321

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-77321 (1)

Vendor Advisories for CVE-2026-77321 (1)

Other References for CVE-2026-77321 (1)

Same Patch Batch · mauriceboe · 2026-09-24 · 4 CVEs total

CVE-2026-77294 8.1 HIGH TREK: Server-Side Request Forgery via User-Configurable LLM Base URL
CVE-2026-77293 7.1 HIGH TREK: Cross-user note-file deletion (IDOR / Broken Access Control)
CVE-2026-77320 5.3 MEDIUM TREK: Public trip share link ignores the `share_map` permission server-side (client-enforc

IV. Related Vulnerabilities

V. Comments for CVE-2026-77321

No comments yet


Leave a comment