CVE-2025-61873

LOW2.6EPSS 0.01%

request-tracker4 - security update

Published: 1/16/2026Modified: 4/28/2026

Description

Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.

Affected packages (5)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1LOW2.6CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N

References (1)