File Upload Vulnerability in TREK Collaborative Travel Planner
CVE-2026-62945

4.3MEDIUM

Key Information:

Vendor

Mauriceboe

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-62945?

The TREK collaborative travel planner prior to version 3.1.3 contains a vulnerability that permits an authenticated user with file-edit permissions to exploit the file upload functionality. This allows the user to submit attacker-controlled identifiers, namely reservation_id, place_id, and assignment_id, without properly validating whether the referenced objects belong to the intended trip. By invoking specific API endpoints, such as POST and PUT methods, a malicious actor can link foreign reservations and access their titles, leading to unauthorized disclosures across private trip boundaries. The issue was rectified in version 3.1.3, which is crucial for securing user data and preserving privacy within the application.

Affected Version(s)

TREK < 3.1.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.