Mauriceboe
Mauriceboe Trek: vulnerabilidades y CVE
Mauriceboe Trek tiene 17 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses17
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85738 | Media (6.3) | 0.30% | — | 24 sept 2026 | TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not recognize NAT64, 6to4, or Teredo IPv6 transition addresses that encode an IPv4 destination. An… |
| CVE-2026-77321 | Media (4.3) | 0.20% | — | 24 sept 2026 | TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiring trips:read and returns core trip summary… |
| CVE-2026-77320 | Media (5.3) | 0.23% | — | 24 sept 2026 | TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns days, assignments, dayNotes, and places through GET /api/shared/:token even when the trip owner… |
| CVE-2026-77294 | Alta (8.1) | 0.31% | — | 24 sept 2026 | TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM_PARSING feature is enabled. Write permission… |
| CVE-2026-77293 | Alta (7.1) | 0.38% | — | 24 sept 2026 | TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against the attacker-controlled tripId but… |
| CVE-2026-78887 | Media (6.3) | 0.46% | — | 25 ago 2026 | A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation can lead to incorrect authorization. The… |
| CVE-2026-78886 | Media (6.3) | 0.58% | — | 25 ago 2026 | A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/src/nest/journey/journey-public.controller.ts of the component Public Journey Photo Proxy.… |
| CVE-2026-78885 | Media (6.3) | 0.58% | — | 25 ago 2026 | A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/services/oidcService.ts of the component OIDC Service. Such manipulation leads… |
| CVE-2026-78864 | Media (5.3) | 0.33% | — | 25 ago 2026 | A vulnerability was determined in liketrek TREK up to 3.0.22. The affected element is the function journeyService.updateEntry of the file server/src/nest/journey/journey.controller.t of the component Journey Entry… |
| CVE-2026-78863 | Media (5.3) | 0.51% | — | 25 ago 2026 | A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. The manipulation results in improper… |
| CVE-2026-62945 | Media (4.3) | 0.34% | — | 20 ago 2026 | TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled reservation_id, place_id, and assignment_id values without using findForeignLinkTarget() to… |
| CVE-2026-54509 | Media (6.5) | 0.41% | — | 20 ago 2026 | TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/routes/journey.ts returns the result of getJourneyShareLink() from… |
| CVE-2026-54508 | Media (5.3) | 0.43% | — | 20 ago 2026 | TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect following in importGoogleList() and importNaverList() in server/src/services/placeService.ts and… |
| CVE-2026-54505 | Baja (2) | 0.58% | — | 20 ago 2026 | TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unescaped activeSuggestion.title value into journey.frontpage.suggestionText through… |
| CVE-2026-45410 | Media (5.3) | 0.34% | — | 28 may 2026 | TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attacker to enumerate valid user accounts via response timing discrepancy. When an email address existed… |
| CVE-2026-40185 | Media (6.5) | 0.36% | — | 10 abr 2026 | TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization checks on the Immich trip photo management routes. This vulnerability is fixed in 2.7.2. |
| CVE-2026-40184 | Media (5.3) | 0.40% | — | 10 abr 2026 | TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. This vulnerability is fixed in 2.7.2. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.