Impact
TREK, a collaborative travel planner, has a blind Server Side Request Forgery flaw due to unvalidated redirect-following. Prior to version 3.1.0 the application accepts an external URL, follows any redirects with fetch() set to "follow", and does not re‑validate the final destination. An attacker can supply a URL that redirects to private or cloud metadata addresses, allowing the server to reach internal services without visible response. The vulnerability is only exploitable by authenticated users: an authenticated trip member can use the list‑import endpoints, and any authenticated user can call the maps resolve endpoint. The attack does not reveal the fetched content, so it is blind, but it grants the attacker internal network access. The flaw is fixed in version 3.1.0.
Affected Systems
The affected system is TREK, the collaborative travel planner produced by mauriceboe. All installations running TREK versions earlier than 3.1.0 are susceptible. No specific patch versions are available prior to 3.1.0; the product must be upgraded to 3.1.0 or later.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Exploitation requires an authenticated user to trigger the vulnerable endpoint; the attacker must be a member of a trip to import a list or any authenticated user to resolve a maps URL. The attack vector is remote, via the web interface, and the outcome is internal network access without any visible response. Because the flaw is blind, detection is difficult, making it a credible threat for organizations that rely on TREK.
OpenCVE Enrichment