CVE-2026-78886 | liketrek TREK up to 3.0.22 Public Journey Photo Proxy journey-public.controller.ts path traversal (GHSA-h66w-m5g2-cqpc)

SecurityVulns

A vulnerability, which was classified as problematic, has been found in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/src/nest/journey/journey-public.controller.ts of the component Public Journey Photo Proxy. Performing a manipulation results in path traversal.

This vulnerability is identified as CVE-2026-78886. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More