File Upload Vulnerability in TREK Collaborative Travel Planner
CVE-2026-62945
4.3MEDIUM
What is CVE-2026-62945?
The TREK collaborative travel planner prior to version 3.1.3 contains a vulnerability that permits an authenticated user with file-edit permissions to exploit the file upload functionality. This allows the user to submit attacker-controlled identifiers, namely reservation_id, place_id, and assignment_id, without properly validating whether the referenced objects belong to the intended trip. By invoking specific API endpoints, such as POST and PUT methods, a malicious actor can link foreign reservations and access their titles, leading to unauthorized disclosures across private trip boundaries. The issue was rectified in version 3.1.3, which is crucial for securing user data and preserving privacy within the application.
Affected Version(s)
TREK < 3.1.3
