CVE-2026-54509

TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/routes/journey.ts returns the result of getJourneyShareLink() from server/src/services/journeyShareService.ts without checking whether the authenticated requester can access the journey. Any ordinary authenticated user can enumerate sequential journey IDs and retrieve tokens from journey_share_tokens for another user's journey. The token grants unauthenticated access through GET /api/public/journey/:token to the shared journey's entries, captions, locations, moods, gallery photos, photo paths, and asset identifiers. This issue is fixed in version 3.1.0.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-20 22:17

Updated : 2026-08-21 15:16


NVD link : CVE-2026-54509

Mitre link : CVE-2026-54509

CVE.ORG link : CVE-2026-54509


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization