CVE-2026-77293
7.1 HIGHpublic exploit availablePublished 2026-09-24 · Updated 2026-09-25
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against the attacker-controlled tripId but deleteNoteFile in server/src/services/collabService.ts resolves the target only by note and file identifiers without requiring the file to belong to that trip. A user with edit access to any trip can submit identifiers belonging to another user's trip and permanently delete that note-file attachment. Sequential identifiers make broad targeting practical, while attachment read operations remain trip-scoped and are not affected. This issue is fixed in version 3.3.0.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Weaknesses
CWE-639, CWE-862
Public exploit & PoC references
- https://github.com/liketrek/TREK/commit/19064b39176660f3be3a2df198c87949504046e2
- https://github.com/liketrek/TREK/pull/1520
- https://github.com/liketrek/TREK/releases/tag/v3.3.0
- https://github.com/liketrek/TREK/security/advisories/GHSA-cjc5-722j-vvmf
- https://github.com/liketrek/TREK/security/advisories/GHSA-cjc5-722j-vvmf
All references
- https://github.com/liketrek/TREK/commit/19064b39176660f3be3a2df198c87949504046e2
- https://github.com/liketrek/TREK/pull/1520
- https://github.com/liketrek/TREK/releases/tag/v3.3.0
- https://github.com/liketrek/TREK/security/advisories/GHSA-cjc5-722j-vvmf
- https://github.com/liketrek/TREK/security/advisories/GHSA-cjc5-722j-vvmf
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-52850PoC
- UNSCOREDCVE-2026-53626PoC
- UNSCOREDCVE-2026-56724PoC
- MEDIUMCVE-2026-61748PoC
- UNSCOREDCVE-2026-63204PoC
- UNSCOREDCVE-2026-63205PoC
- MEDIUMCVE-2026-69190PoC
- HIGHCVE-2026-76087PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.