CVE-2026-44227

Source
https://cve.org/CVERecord?id=CVE-2026-44227
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44227.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44227
Aliases
  • GHSA-7742-fhq7-ggv9
Downstream
Published
2026-07-20T17:32:48Z
Modified
2026-08-12T03:51:28Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
RT: Reflected Cross-Site Scripting via URL parameters
Details

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session. There are no effective workarounds. Avoid following untrusted RT URLs. This issue has been fixed in version 6.0.3.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44227.json"
}
References

Affected packages

Git / github.com/bestpractical/rt

Affected ranges

Type
GIT
Repo
https://github.com/bestpractical/rt
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:bestpractical:request_tracker:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "6.0.0"
        },
        {
            "fixed": "6.0.3"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44227.json"