CyberRota Analysis
AI-GeneratedThe vulnerability allows authenticated users to delete note-file attachments from trips they do not own by exploiting the DELETE endpoint, which improperly authorizes requests based solely on note and file identifiers rather than the associated trip. This could lead to unauthorized data loss for users, as attackers can target attachments across different trips. Organizations using versions prior to 3.3.0 should prioritize this issue to prevent potential data manipulation and loss.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against the attacker-controlled tripId but deleteNoteFile in server/src/services/collabService.ts resolves the target only by note and file identifiers without requiring the file to belong to that trip. A user with edit access to any trip can submit identifiers belonging to another user's trip and permanently delete that note-file attachment. Sequential identifiers make broad targeting practical, while attachment read operations remain trip-scoped and are not affected. This issue is fixed in version 3.3.0.