CVE-2026-77294
Last modified
CVE-2026-77294 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM_PARSING feature is enabled.
Description
TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM_PARSING feature is enabled. Write permission to the target trip instance is required to trigger the vulnerable AI-assisted import path. The value is consumed by the clients in server/src/nest/llm-parse/clients/openai-compatible.client.ts, server/src/nest/llm-parse/clients/anthropic.client.ts, and server/src/nest/llm-parse/router/ollama-format.client.ts without applying the server-side request forgery guard. Triggering AI-assisted trip parsing causes the server to request the supplied destination, and upstream error response text can be returned in parsing warnings. This permits internal service discovery and access to link-local cloud metadata, with possible disclosure of infrastructure credentials and subsequent modification of protected cloud resources. This issue is fixed in version 3.3.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| mauriceboe | TREK | < 3.3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-77294?
How severe is CVE-2026-77294?
How do I fix CVE-2026-77294?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-77274MCP Atlassian is a Model Context Protocol (MCP) server for A…8.8
- CVE-2026-7728A vulnerability was identified in ryanjoachim mcp-rtfm 0.1.0…6.3
- CVE-2026-77281Caddy is an extensible server platform that uses TLS by defa…6.5
- CVE-2026-77285OpenBao is an open source identity-based secrets management …2.4
- CVE-2026-7729A security flaw has been discovered in pixelsock directus-mc…6.3
- CVE-2026-77293TREK is a collaborative travel planner. Prior to 3.3.0, the …7.1
- CVE-2026-77298SeaweedFS is a distributed storage system for files and blob…8.7
- CVE-2026-7730A weakness has been identified in privsim mcp-test-runner 0.…6.3
- CVE-2026-77301adm-zip is a JavaScript library for creating and extracting …7.5
- CVE-2026-7731A security vulnerability has been detected in code-projects …6.3
- CVE-2026-77310jackson-databind contains the general-purpose data-binding f…5.3
- CVE-2026-77317SeaweedFS is a distributed storage system for files and blob…8.1
Are you affected by CVE-2026-77294?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
