If you believe you've discovered a security issue in RT, please send an
email to security@bestpractical.com with a detailed description of the
issue, and a secure means to respond to you (such as your PGP public
key). You can find our PGP key and fingerprint at
https://bestpractical.com/security/.
Security: bestpractical/rt
Security
SECURITY.md
-
Reflected Cross-Site Scripting in search results chartGHSA-p724-v26h-32g9 published
May 20, 2026 by cbrandtbuffaloModerate -
Privilege escalation and information disclosure via REST 2.0 user collection endpointGHSA-7rx2-x357-wv74 published
May 20, 2026 by cbrandtbuffaloCritical -
Cross-Site Scripting via inline-served uploaded contentGHSA-x576-pvwp-c2qv published
May 20, 2026 by cbrandtbuffaloModerate -
Stored Cross-Site Scripting via insufficient template escapingGHSA-pfgp-5j8g-phgc published
May 20, 2026 by cbrandtbuffaloModerate -
Reflected Cross-Site Scripting via URL parametersGHSA-7742-fhq7-ggv9 published
May 20, 2026 by cbrandtbuffaloModerate -
LDAP authentication bypass via empty passwordGHSA-3w28-fmcr-mjjx published
May 20, 2026 by cbrandtbuffaloHigh -
SQL injection via entry_aggregator parameter in JSON searchGHSA-7vf8-xv7w-97c6 published
May 20, 2026 by cbrandtbuffaloHigh -
CSRF protection broken for authenticated users in RT 6GHSA-265j-qx4w-256j published
May 20, 2026 by cbrandtbuffaloHigh -
Spreadsheet downloads vulnerable to CSV/formula injection in Microsoft Excel and similar appsGHSA-6x92-7v65-7m3r published
May 20, 2026 by cbrandtbuffaloModerate
Learn more about advisories related to bestpractical/rt in the GitHub Advisory Database