Executive brief
TREK, a collaborative travel planning application, was found to serve uploaded trip photos without requiring any user login. This means that if an unauthorized person knows or guesses the specific filename of an uploaded photo, they can view it directly over the internet. This could lead to the exposure of private travel photos and personal information shared within the app.
Technical details
A missing authentication vulnerability (CWE-306) existed in TREK's handling of uploaded media. Specifically, the `/uploads/photos/:filename` route was served publicly, failing to verify if the requester possessed a valid JSON Web Token (JWT) or a legitimate share token. While the attack complexity is rated as high—likely due to the need to know or brute-force specific filenames—an unauthenticated remote attacker could bypass intended access controls to view private trip photos. This issue was addressed in version 2.7.2 by implementing mandatory authentication checks for the affected route, while keeping avatars and covers public for functional requirements.
Affected products
- mauriceboe TREK < 2.7.2
Timeline
- 2026-04-01: patched: Fix committed and version 2.7.2 released.
- 2026-04-10: disclosed: CVE published to NVD.