CVE-2026-44229

Source
https://cve.org/CVERecord?id=CVE-2026-44229
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-44229.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-44229
Aliases
  • GHSA-x576-pvwp-c2qv
Downstream
Published
2026-07-20T19:18:25.818Z
Modified
2026-07-25T03:32:06.194034266Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
RT: Cross-Site Scripting via inline-served uploaded content
Details

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include JavaScript in the upload that will execute in the browser session of any RT user who later views or downloads it. This issue has been fixed in versions 5.0.10 and 6.0.3.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44229.json"
}
References

Affected packages

Git / github.com/bestpractical/rt

Affected ranges

Type
GIT
Repo
https://github.com/bestpractical/rt
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "6.0.0"
        },
        {
            "fixed": "6.0.3"
        },
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.0.10"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-44229.json"