5.3

CVE-2026-40184

Unauthenticated Access to Uploaded Files in TREK

TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. This vulnerability is fixed in 2.7.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MauriceboeTrek Version <= 2.7.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.142
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
security-advisories@github.com 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

https://github.com/mauriceboe/TREK/security/advisories/GHSA-wxx3-84fc-mrx2
Vendor Advisory
https://github.com/mauriceboe/TREK/commit/16277a3811a00c2983f7486fee83c112986cb179
Patch
https://github.com/mauriceboe/TREK/releases/tag/v2.7.2
Release Notes