mauriceboe TREK
4 known vulnerabilities in mauriceboe TREK, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-77321 CVSS 4.3 medium TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for…
- CVE-2026-77320 CVSS 5.3 medium TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns days…
- CVE-2026-77294 CVSS 8.1 high TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url…
- CVE-2026-77293 CVSS 7.1 high TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint…