TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/routes/journey.ts returns the result of getJourneyShareLink() from server/src/services/journeyShareService.ts without checking whether the authenticated requester can access the journey. Any ordinary authenticated user can enumerate sequential journey IDs and retrieve tokens from journey_share_tokens for another user's journey. The token grants unauthenticated access through GET /api/public/journey/:token to the shared journey's entries, captions, locations, moods, gallery photos, photo paths, and asset identifiers. This issue is fixed in version 3.1.0.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-20 22:17
Updated : 2026-08-21 15:16
NVD link : CVE-2026-54509
Mitre link : CVE-2026-54509
CVE.ORG link : CVE-2026-54509
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
