Path Traversal Vulnerability in liketrek TREK Software
CVE-2026-78886
6.3MEDIUM
What is CVE-2026-78886?
A security flaw exists within liketrek's TREK software, particularly affecting the Public Journey Photo Proxy component. The vulnerability is rooted in an unknown function of the file server/src/nest/journey/journey-public.controller.ts, allowing for path traversal attacks. This weakness can be exploited remotely, posing significant risks to the integrity of file system data. To mitigate the threat, users are strongly advised to upgrade to version 3.1.0, which addresses this vulnerability.
Affected Version(s)
TREK 3.0.0
TREK 3.0.1
TREK 3.0.2
