PT-2026-45152 · Rt · Rt

CVE-2026-44227

·

Published

2026-05-20

·

Updated

2026-08-07

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions RT versions 6.0.0 through 6.0.2
Description An issue exists where an authenticated user can be induced to visit a crafted URL, allowing an attacker to execute arbitrary JavaScript within the user's browser session via reflected Cross-Site Scripting (XSS). Cross-Site Scripting is a technique where malicious scripts are injected into otherwise trusted websites.
Recommendations Update to version 6.0.3. Avoid following untrusted RT URLs.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44227
GHSA-7742-FHQ7-GGV9

Affected Products

Rt