CVE-2026-78864 | liketrek TREK up to 3.0.22 Journey Entry Update journey.controller.t journeyService.updateEntry sql injection (GHSA-627x-pmfq-98qv)
A vulnerability classified as critical has been found in liketrek TREK up to 3.0.22. The affected element is the function journeyService.updateEntry of the file server/src/nest/journey/journey.controller.t of the component Journey Entry Update. This manipulation causes sql injection.
The identification of this vulnerability is CVE-2026-78864. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More