Impact
A vulnerability was identified in liketrek TREK's Public Journey Photo Proxy, specifically in journey-public.controller.ts, that allows an attacker to manipulate the file path used by the server to serve photos. The flaw leads to a classic path traversal, enabling remote retrieval of arbitrary files on the underlying filesystem. The attacker can exploit this over the network; the vulnerability is considered high in complexity and difficult to exploit.
Affected Systems
The affected product is liketrek TREK, versions up to and including 3.0.22. The recommendation is to upgrade to version 3.1.0 or later, where the issue has been mitigated. No other vendors or product variants are listed as affected.
Risk and Exploitability
The CVSS score for this vulnerability is 6.3, indicating moderate severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. Attack can be initiated remotely via the public photo proxy URL. Because of the high complexity and difficult exploitability, the likelihood of exploitation is moderate but should not be ignored. Monitoring traffic for suspicious file requests and applying the available patch remain the most effective defenses.
OpenCVE Enrichment