PT-2026-33458 · Lukevella · Rallly

Trebledj

·

Published

2026-04-17

·

Updated

2026-04-19

·

CVE-2026-6493

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions lukevella rallly versions prior to 4.8.0
Description A flaw in the Reset Password Handler component within the file 'apps/web/src/app/[locale]/(auth)/reset-password/components/reset-password-form.tsx' allows for remote cross site scripting. This occurs through the manipulation of the redirectTo argument.
Recommendations Update to version 4.8.0.

Exploit

Fix

Code Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-6493

Affected Products

Rallly