CVE-2026-78886

Source
https://cve.org/CVERecord?id=CVE-2026-78886
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78886.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-78886
Aliases
  • GHSA-h66w-m5g2-cqpc
Published
2026-08-25T12:30:09.424Z
Modified
2026-08-28T11:30:36.400064036Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversal
Details

A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/src/nest/journey/journey-public.controller.ts of the component Public Journey Photo Proxy. Performing a manipulation results in path traversal. The attack can be initiated remotely. The attack's complexity is rated as high. The exploitability is reported as difficult. Upgrading to version 3.1.0 mitigates this issue. It is advisable to upgrade the affected component.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78886.json",
    "cwe_ids": [
        "CWE-22"
    ],
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/liketrek/trek

Affected ranges

Type
GIT
Repo
https://github.com/liketrek/trek
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "3.0.0"
        },
        {
            "last_affected": "3.0.0"
        },
        {
            "introduced": "3.0.1"
        },
        {
            "last_affected": "3.0.1"
        },
        {
            "introduced": "3.0.2"
        },
        {
            "last_affected": "3.0.2"
        },
        {
            "introduced": "3.0.3"
        },
        {
            "last_affected": "3.0.3"
        },
        {
            "introduced": "3.0.4"
        },
        {
            "last_affected": "3.0.4"
        },
        {
            "introduced": "3.0.5"
        },
        {
            "last_affected": "3.0.5"
        },
        {
            "introduced": "3.0.6"
        },
        {
            "last_affected": "3.0.6"
        },
        {
            "introduced": "3.0.7"
        },
        {
            "last_affected": "3.0.7"
        },
        {
            "introduced": "3.0.8"
        },
        {
            "last_affected": "3.0.8"
        },
        {
            "introduced": "3.0.9"
        },
        {
            "last_affected": "3.0.9"
        },
        {
            "introduced": "3.0.10"
        },
        {
            "last_affected": "3.0.10"
        },
        {
            "introduced": "3.0.11"
        },
        {
            "last_affected": "3.0.11"
        },
        {
            "introduced": "3.0.12"
        },
        {
            "last_affected": "3.0.12"
        },
        {
            "introduced": "3.0.13"
        },
        {
            "last_affected": "3.0.13"
        },
        {
            "introduced": "3.0.14"
        },
        {
            "last_affected": "3.0.14"
        },
        {
            "introduced": "3.0.15"
        },
        {
            "last_affected": "3.0.15"
        },
        {
            "introduced": "3.0.16"
        },
        {
            "last_affected": "3.0.16"
        },
        {
            "introduced": "3.0.17"
        },
        {
            "last_affected": "3.0.17"
        },
        {
            "introduced": "3.0.18"
        },
        {
            "last_affected": "3.0.18"
        },
        {
            "introduced": "3.0.19"
        },
        {
            "last_affected": "3.0.19"
        },
        {
            "introduced": "3.0.20"
        },
        {
            "last_affected": "3.0.20"
        },
        {
            "introduced": "3.0.21"
        },
        {
            "last_affected": "3.0.21"
        },
        {
            "introduced": "3.0.22"
        },
        {
            "last_affected": "3.0.22"
        }
    ]
}

Affected versions

3.*
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
v3.*
v3.0.0
v3.0.1
v3.0.10
v3.0.11
v3.0.12
v3.0.13
v3.0.14
v3.0.15
v3.0.16
v3.0.17
v3.0.18
v3.0.19
v3.0.2
v3.0.20
v3.0.21
v3.0.22
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78886.json"