Executive brief
Request Tracker (RT), a popular enterprise-grade ticket and issue tracking system, is vulnerable to a security flaw where malicious code can be executed in a user's browser. By tricking an authenticated user into clicking a specially crafted link, an attacker can perform actions on the user's behalf or steal sensitive session information. This could lead to unauthorized access to support tickets or administrative functions depending on the victim's permissions.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in RT versions 6.0.0 through 6.0.2. The flaw is located in the handling of additional URL parameters on search pages, where user-supplied input is insufficiently sanitized before being rendered in the web interface. An unauthenticated remote attacker can exploit this by crafting a malicious URL and using social engineering to entice an authenticated RT user to click it. Successful exploitation allows the execution of arbitrary JavaScript within the victim's browser session, potentially leading to session hijacking or unauthorized state-changing actions. The issue is resolved in version 6.0.3.
Affected products
- Best Practical Solutions RT >= 6.0.0, < 6.0.3
Timeline
- 2026-05-20: patched: Fixed in RT version 6.0.3
- 2026-05-20: advisory: GitHub Security Advisory GHSA-7742-fhq7-ggv9 published
- 2026-07-20: disclosed: CVE-2026-44227 published to NVD