Executive brief
TREK is a self-hosted expense and trip-tracking application. The OIDC (single sign-on) login function fails to verify email addresses, allowing an attacker with access to a permissive identity provider to claim an existing user's email address and hijack their account permanently.
Technical details
The vulnerability exists in the findOrCreateUser function of server/src/services/oidcService.ts. When an OIDC identity provider logs in a user, the function matches incoming SSO identities to existing local accounts by comparing email addresses (case-insensitive) without verifying the email_verified claim from the provider. An attacker using an identity provider that does not enforce email verification can set their profile email to match a victim's email address; when they log in via OIDC, their identity is auto-linked to the victim's account, granting persistent account access. The attack requires network access and a permissive identity provider (high attack complexity). The fix, deployed in version 3.1.0, requires email_verified to be true before auto-linking to an existing account; otherwise login is rejected with an oidc_error.
Affected products
- liketrek TREK up to 3.0.22
Timeline
- 2026-06-16: disclosed: Fixed in v3.1.0 release
- 2026-06-16: advisory: GHSA-fvgw-r58q-4cw4 published