PatchSiren

liketrek CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM liketrek CVE published 2026-09-24

CVE-2026-85738

TREK collaborative travel planner has a Server-Side Request Forgery (SSRF) vulnerability prior to version 3.4.0. The checkSsrf logic does not recognize certain IPv6 transition addresses, allowing an authenticated user to bypass protections and potentially access internal services or cloud metadata. This issue can lead to information exposure in deployments that route specific IPv6 transition formats. Defe [truncated]