Junglewise Threat Intelligence

CVE-2026-78864: liketrek TREK SQL injection in journey entry update

CVE-2026-78864 · Severity: medium · CVSS 6.3 · Published 2026-08-25

Technologies: Liketrek TREK. Vendors: Liketrek.

Executive brief

TREK is a privacy-focused trip planning and expense-tracking application. A low-privilege authenticated user can inject SQL through unvalidated column names in the journey entry update endpoint, allowing them to read sensitive data from the entire database (including user passwords and encryption keys) and impersonate other trip authors. This could lead to account takeover and exposure of private trip information.

Technical details

The vulnerability is a SQL injection in the journeyService.updateEntry function (PATCH /api/journeys/entries/:id in journey.controller.ts). The NestJS endpoint accepts raw request body keys without validation and constructs UPDATE statements using these keys directly in the SQL string (e.g., UPDATE journey_entries SET ${key} = ?), while only parameterizing values. An authenticated user can inject malicious column names containing subqueries to exfiltrate data from any table or mass-assign protected columns like author_id and visibility. The fix applies a column allow-list to the updateEntry function, mirroring the safe pattern already used elsewhere in the codebase. Patch is available in version 3.1.0.

Affected products

  • liketrek TREK up to 3.0.22

Timeline

  • 2026-06-16: disclosed: Coordinated private disclosure reported by Gabriel ByteJMP
  • 2026-06-16: patched: Fixed in version 3.1.0
  • 2026-08-25: advisory: CVE-2026-78864 published

References