GHSA-q5wr-f3rq-qfcgMediumCVSS 5.6
A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/services/oidcService.ts of the component OIDC Service. Such manipulation leads to improper authentication. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is regarded as difficult. Upgrading to version 3.1.0 is sufficient to resolve this issue. Upgrading the affected component is advised.
🔗 References (8)
- https://github.com/mauriceboe/TREK/security/advisories/GHSA-fvgw-r58q-4cw4
- https://nvd.nist.gov/vuln/detail/CVE-2026-78885
- https://github.com/liketrek/TREK/releases/tag/v3.1.0
- https://vuldb.com/cve/CVE-2026-78885
- https://vuldb.com/submit/886931
- https://vuldb.com/vuln/394941
- https://vuldb.com/vuln/394941/cti
- https://github.com/advisories/GHSA-q5wr-f3rq-qfcg