PT-2026-45153 · Rt+1 · Rt+1

CVE-2026-44229

·

Published

2026-05-20

·

Updated

2026-07-20

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions RT versions 5.0.0 through 5.0.9 RT versions 6.0.0 through 6.0.2
Description An issue exists where uploaded content is served inline instead of as an attachment. An authenticated user with upload permissions can include JavaScript in the uploaded content, which then executes in the browser session of any user who views or downloads the file. This is a Cross-Site Scripting (XSS) flaw, which occurs when an application includes untrusted data in a web page without proper validation or escaping.
Recommendations Update RT versions 5.0.0 through 5.0.9 to version 5.0.10. Update RT versions 6.0.0 through 6.0.2 to version 6.0.3.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44229
GHSA-X576-PVWP-C2QV
USN-8506-1

Affected Products

Linuxmint
Rt