Information Disclosure Vulnerability in TREK Collaborative Travel Planner
CVE-2026-54509
6.5MEDIUM
What is CVE-2026-54509?
A vulnerability exists in the TREK Collaborative Travel Planner affecting versions 3.0.0 to 3.1.0. In this specific version, the API route for sharing journeys does not adequately verify whether the authenticated user is authorized to access the requested journey. Consequently, an authenticated user can exploit this flaw by enumerating journey IDs, allowing them to retrieve tokens linked to other users' journeys. These tokens enable unauthorized access to various shared journey details, including entries, captions, moods, and gallery photos. This vulnerability poses significant risks to user privacy and data confidentiality, and it has been addressed in version 3.1.0.
Affected Version(s)
TREK >= 3.0.0, < 3.1.0
