CVE-2026-77294 | mauriceboe TREK up to 3.2.x LLM Parsing openai-compatible.client.ts llm_base_url server-side request forgery
A vulnerability was found in mauriceboe TREK up to 3.2.x. It has been rated as critical. The affected element is an unknown function of the file server/src/nest/llm-parse/clients/openai-compatible.client.ts of the component LLM Parsing. The manipulation of the argument llm_base_url leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-77294. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More