CVE-2026-77321: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in mauriceboe TREK
TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiring trips:read and returns core trip summary data regardless of the delegated scopes. A token granted only an unrelated capability, such as weather:read, can receive trip metadata, member email addresses from server/src/services/tripService.ts, itinerary days, and accommodations for every trip accessible to the token's user. Cross-user trip authorization remains enforced, but the missing scope check defeats the consented least-privilege boundary and exposes trip content and third-party contact information to an MCP client that was not authorized to read it. This issue is fixed in version 3.3.0.
AI Analysis
Technical Summary
The vulnerability in mauriceboe TREK affects the get_trip_summary tool in server/src/mcp/tools/trips.ts. Before version 3.3.0, this tool is registered for scoped OAuth MCP tokens without enforcing the trips:read scope. Consequently, tokens granted unrelated capabilities (e.g., weather:read) can retrieve sensitive trip data including metadata, member emails, itinerary days, and accommodations for trips accessible to the token's user. While cross-user authorization remains intact, the missing scope validation breaks the least-privilege principle, exposing sensitive information to unauthorized clients. This vulnerability is addressed in version 3.3.0.
Potential Impact
An attacker or unauthorized client holding an OAuth token without the trips:read scope but with other unrelated scopes can access sensitive trip information such as metadata, member email addresses, itinerary details, and accommodations. This exposure violates the principle of least privilege and could lead to unauthorized disclosure of personal and trip-related data. There is no indication of integrity or availability impact. Cross-user access controls remain effective, limiting exposure to data of the token's user only.
Mitigation Recommendations
Upgrade mauriceboe TREK to version 3.3.0 or later, where this issue is fixed by enforcing the trips:read scope check on the get_trip_summary tool. No other mitigations are indicated or required.
CVE-2026-77321: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in mauriceboe TREK
Description
TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiring trips:read and returns core trip summary data regardless of the delegated scopes. A token granted only an unrelated capability, such as weather:read, can receive trip metadata, member email addresses from server/src/services/tripService.ts, itinerary days, and accommodations for every trip accessible to the token's user. Cross-user trip authorization remains enforced, but the missing scope check defeats the consented least-privilege boundary and exposes trip content and third-party contact information to an MCP client that was not authorized to read it. This issue is fixed in version 3.3.0.
CVSS v3.1
Score 4.3medium
Affected software
mauriceboe
TREK
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in mauriceboe TREK affects the get_trip_summary tool in server/src/mcp/tools/trips.ts. Before version 3.3.0, this tool is registered for scoped OAuth MCP tokens without enforcing the trips:read scope. Consequently, tokens granted unrelated capabilities (e.g., weather:read) can retrieve sensitive trip data including metadata, member emails, itinerary days, and accommodations for trips accessible to the token's user. While cross-user authorization remains intact, the missing scope validation breaks the least-privilege principle, exposing sensitive information to unauthorized clients. This vulnerability is addressed in version 3.3.0.
Potential Impact
An attacker or unauthorized client holding an OAuth token without the trips:read scope but with other unrelated scopes can access sensitive trip information such as metadata, member email addresses, itinerary details, and accommodations. This exposure violates the principle of least privilege and could lead to unauthorized disclosure of personal and trip-related data. There is no indication of integrity or availability impact. Cross-user access controls remain effective, limiting exposure to data of the token's user only.
Mitigation Recommendations
Upgrade mauriceboe TREK to version 3.3.0 or later, where this issue is fixed by enforcing the trips:read scope check on the get_trip_summary tool. No other mitigations are indicated or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-20T19:24:11.617Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab56ceaf7a7c54106ad2a28
Added to database: 09/24/2026, 18:33:14 UTC
Last enriched: 09/24/2026, 18:48:20 UTC
Last updated: 09/25/2026, 03:13:20 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.