MEDIUM
liketrek
CVE published 2026-09-24
CVE-2026-85738
TREK collaborative travel planner has a Server-Side Request Forgery (SSRF) vulnerability prior to version 3.4.0. The checkSsrf logic does not recognize certain IPv6 transition addresses, allowing an authenticated user to bypass protections and potentially access internal services or cloud metadata. This issue can lead to information exposure in deployments that route specific IPv6 transition formats. Defe [truncated]