mauriceboe TREK

4 known vulnerabilities in mauriceboe TREK, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-77321 CVSS 4.3 medium TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for…
  • CVE-2026-77320 CVSS 5.3 medium TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns days…
  • CVE-2026-77294 CVSS 8.1 high TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url…
  • CVE-2026-77293 CVSS 7.1 high TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint…