RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session. There are no effective workarounds. Avoid following untrusted RT URLs. This issue has been fixed in version 6.0.3.
References
| Link | Resource |
|---|---|
| https://github.com/bestpractical/rt/releases/tag/rt-6.0.3 | Release Notes |
| https://github.com/bestpractical/rt/security/advisories/GHSA-7742-fhq7-ggv9 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-20 18:16
Updated : 2026-08-07 13:25
NVD link : CVE-2026-44227
Mitre link : CVE-2026-44227
CVE.ORG link : CVE-2026-44227
JSON object : View
Products Affected
bestpractical
- request_tracker
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
