CVE-2026-78886

A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/src/nest/journey/journey-public.controller.ts of the component Public Journey Photo Proxy. Performing a manipulation results in path traversal. The attack can be initiated remotely. The attack's complexity is rated as high. The exploitability is reported as difficult. Upgrading to version 3.1.0 mitigates this issue. It is advisable to upgrade the affected component.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-25 13:19

Updated : 2026-08-26 16:19


NVD link : CVE-2026-78886

Mitre link : CVE-2026-78886

CVE.ORG link : CVE-2026-78886


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')