Content Spoofing Vulnerability in TREK Travel Planner Due to Improper HTML Handling
CVE-2026-54505

2LOW

Key Information:

Vendor

Mauriceboe

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-54505?

The TREK Travel Planner, when using the Journey add-on, is susceptible to a content spoofing vulnerability prior to version 3.1.0. This occurs when HTML content can be embedded into the trip title by a trip owner, which is then transmitted to collaborators accessing the journey. The application incorporates this unescaped content within the DOM through the dangerous use of dangerouslySetInnerHTML, allowing malicious markup to be rendered in the UI. Although the platform employs a Content Security Policy to mitigate certain risks, it does not fully prevent content spoofing. This vulnerability compromises the integrity of the application and can mislead users, making it crucial for users to upgrade to version 3.1.0 or later, where this issue has been addressed.

Affected Version(s)

TREK < 3.1.0

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.