Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-85738— TREK: SSRF Guard Bypass via IPv6 Transition Addresses (NAT64/6to4)

Quick assessment

Affected
liketrek TREK
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

TREK 是一款协同旅行规划工具。在版本 3.4.0 之前,位于 中的 checkSsrf 逻辑未能正确识别用于编码 IPv4 目标的 NAT64、6to4 或 Teredo 等 IPv6 过渡地址。经过身份验证的用户若控制某个 DNS 记录,可提供一个 URL,其 AAAA 记录解析结果为一个 IPv6 过渡地址,该地址内嵌了私有地址、回环地址或链路本地地址等 IPv4 目标。此时, 和 函数会错误地将此类地址判断为允许访问。在部署环境中,若存在对相应过渡格式的路由支持,则面向用户的导入功能、Webhook、集成

CVSS 6.3 · Medium EPSS 0.30% · P21

Affected Version Matrix 1

VendorProduct Version RangeStatus
liketrek TREK < 3.4.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85738

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
TREK: SSRF Guard Bypass via IPv6 Transition Addresses (NAT64/6to4)
Source: CVE Program / CVE List V5
Vulnerability Description
TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not recognize NAT64, 6to4, or Teredo IPv6 transition addresses that encode an IPv4 destination. An authenticated user who controls a DNS record can supply a URL whose AAAA result is a transition address embedding a private, loopback, or link-local IPv4 target, and isAlwaysBlocked and isPrivateNetwork classify the address as allowed. In a deployment that routes the applicable transition format, user-facing imports, webhooks, integrations, or plugin egress can reach internal services or cloud metadata and expose returned information. This issue is fixed in version 3.4.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
liketrek TREK < 3.4.0 -

II. Public POCs for CVE-2026-85738

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85738

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-85738 (1)

Vendor Advisories for CVE-2026-85738 (1)

Vendor Pages for CVE-2026-85738 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85738

No comments yet


Leave a comment