Reflected XSS Vulnerability in RT Issue Tracking System by Best Practical
CVE-2026-44227
6.1MEDIUM
What is CVE-2026-44227?
An open-source issue tracking system known as RT (Request Tracker) has a reflected Cross-Site Scripting (XSS) vulnerability present in versions 6.0.0 through 6.0.2. This flaw allows an attacker to exploit the system by convincing an authenticated user to click on a maliciously crafted URL, thereby executing arbitrary JavaScript within the victim's browser session. As a result, there are significant security implications for users of these RT versions, particularly as there are no known effective workarounds. Users are advised to refrain from clicking on untrusted RT URLs. This issue has been addressed in RT version 6.0.3.
Affected Version(s)
rt >= 6.0.0, < 6.0.3
