CVE-2026-77320: TREK: Public trip share link ignores the `share_map` permission server-side (client-enforced authorization → itinerary/location disclosure)

Published Sep 24, 2026
·
Updated

TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns days, assignments, dayNotes, and places through GET /api/shared/:token even when the trip owner disables sharemap. The client hides the map, but the public JSON response still includes the itinerary and place names, coordinates, addresses, descriptions, notes, and prices. Anyone holding the valid share token can therefore read location and route information that the owner explicitly chose not to share, although the random token remains required and the flaw does not permit modification. This issue is fixed in version 3.3.0.

Affected Software

1 affected component
TREK TREK<3.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade TREK to a version that resolves this vulnerability.

    Fixed in 3.3.0

Event History

Sep 24, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can access the information exposed by this issue?

Anyone who possesses a valid public trip share token can retrieve the shared trip data. No authentication or additional privileges are required, but the random token is still required.

2

What information may be disclosed?

The public response can include itinerary days, assignments, day notes, and place data such as names, coordinates, addresses, descriptions, notes, and prices. The issue does not allow trip modification.

3

Are trips affected when map sharing is disabled?

Yes. In affected versions, disabling share_map only hides the map in the client; the server still returns the underlying itinerary and location data from the public shared-trip endpoint.

4

Which versions are affected and what is the remediation?

TREK versions prior to 3.3.0 are affected. Upgrade to version 3.3.0, which fixes the server-side permission enforcement.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203