CVE-2026-78887

Source
https://cve.org/CVERecord?id=CVE-2026-78887
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78887.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-78887
Aliases
  • GHSA-24x9-fcj9-vp6w
Published
2026-08-25T12:45:10.723Z
Modified
2026-08-28T11:30:39.530160576Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
liketrek TREK Journey Photo Proxy validateShareTokenForAsset authorization
Details

A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation can lead to incorrect authorization. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is said to be difficult. Upgrading to version 3.1.0 will fix this issue. You should upgrade the affected component.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78887.json",
    "cwe_ids": [
        "CWE-285",
        "CWE-863"
    ],
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/liketrek/trek

Affected ranges

Type
GIT
Repo
https://github.com/liketrek/trek
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "3.0.0"
        },
        {
            "last_affected": "3.0.0"
        },
        {
            "introduced": "3.0.1"
        },
        {
            "last_affected": "3.0.1"
        },
        {
            "introduced": "3.0.2"
        },
        {
            "last_affected": "3.0.2"
        },
        {
            "introduced": "3.0.3"
        },
        {
            "last_affected": "3.0.3"
        },
        {
            "introduced": "3.0.4"
        },
        {
            "last_affected": "3.0.4"
        },
        {
            "introduced": "3.0.5"
        },
        {
            "last_affected": "3.0.5"
        },
        {
            "introduced": "3.0.6"
        },
        {
            "last_affected": "3.0.6"
        },
        {
            "introduced": "3.0.7"
        },
        {
            "last_affected": "3.0.7"
        },
        {
            "introduced": "3.0.8"
        },
        {
            "last_affected": "3.0.8"
        },
        {
            "introduced": "3.0.9"
        },
        {
            "last_affected": "3.0.9"
        },
        {
            "introduced": "3.0.10"
        },
        {
            "last_affected": "3.0.10"
        },
        {
            "introduced": "3.0.11"
        },
        {
            "last_affected": "3.0.11"
        },
        {
            "introduced": "3.0.12"
        },
        {
            "last_affected": "3.0.12"
        },
        {
            "introduced": "3.0.13"
        },
        {
            "last_affected": "3.0.13"
        },
        {
            "introduced": "3.0.14"
        },
        {
            "last_affected": "3.0.14"
        },
        {
            "introduced": "3.0.15"
        },
        {
            "last_affected": "3.0.15"
        },
        {
            "introduced": "3.0.16"
        },
        {
            "last_affected": "3.0.16"
        },
        {
            "introduced": "3.0.17"
        },
        {
            "last_affected": "3.0.17"
        },
        {
            "introduced": "3.0.18"
        },
        {
            "last_affected": "3.0.18"
        },
        {
            "introduced": "3.0.19"
        },
        {
            "last_affected": "3.0.19"
        },
        {
            "introduced": "3.0.20"
        },
        {
            "last_affected": "3.0.20"
        },
        {
            "introduced": "3.0.21"
        },
        {
            "last_affected": "3.0.21"
        },
        {
            "introduced": "3.0.22"
        },
        {
            "last_affected": "3.0.22"
        }
    ]
}

Affected versions

3.*
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
v3.*
v3.0.0
v3.0.1
v3.0.10
v3.0.11
v3.0.12
v3.0.13
v3.0.14
v3.0.15
v3.0.16
v3.0.17
v3.0.18
v3.0.19
v3.0.2
v3.0.20
v3.0.21
v3.0.22
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78887.json"