Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/src/nest/journey/journey-public.controller.ts of the component Public Journey Photo Proxy. Performing a manipulation results in path traversal. The attack can be initiated remotely. The attack's complexity is rated as high. The exploitability is reported as difficult. Upgrading to version 3.1.0 mitigates this issue. It is advisable to upgrade the affected component. | |
| Title | liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversal | |
| First Time appeared |
Liketrek
Liketrek trek |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:liketrek:trek:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Liketrek
Liketrek trek |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-25T13:13:00.971Z
Reserved: 2026-08-25T06:01:26.170Z
Link: CVE-2026-78886
No data.
Status : Received
Published: 2026-08-25T13:19:32.013
Modified: 2026-08-25T13:19:32.013
Link: CVE-2026-78886
No data.
OpenCVE Enrichment
No data.
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')