Content Spoofing Vulnerability in TREK Travel Planner Due to Improper HTML Handling
CVE-2026-54505
What is CVE-2026-54505?
The TREK Travel Planner, when using the Journey add-on, is susceptible to a content spoofing vulnerability prior to version 3.1.0. This occurs when HTML content can be embedded into the trip title by a trip owner, which is then transmitted to collaborators accessing the journey. The application incorporates this unescaped content within the DOM through the dangerous use of dangerouslySetInnerHTML, allowing malicious markup to be rendered in the UI. Although the platform employs a Content Security Policy to mitigate certain risks, it does not fully prevent content spoofing. This vulnerability compromises the integrity of the application and can mislead users, making it crucial for users to upgrade to version 3.1.0 or later, where this issue has been addressed.
Affected Version(s)
TREK < 3.1.0
