OVERVIEW CVE-2026-6493 is a cross-site scripting (XSS) vulnerability affecting lukevella rallly versions up to 4.7.4. The flaw exists in the Reset Password Handler component, specifically within the reset-password-form.tsx file, where improper validation of the redirectTo argument allows attackers to inject malicious scripts. This vulnerability has a published exploit available in the public domain. SEVERITY The vulnerability carries a CVSS v3.1 score of 3.5 (LOW) with a network-based attack vector requiring low complexity and user interaction. Attack prerequisites include valid authentication credentials. The impact is limited to integrity violations with no confidentiality or availability impact. However, the FAUCET Risk Score of 28.0/100 suggests moderate organizational risk when considering real-world exploitation factors and attack complexity. EXPLOITATION STATUS While the CVSS and EPSS scores indicate low baseline threat levels, the vulnerability is listed on the Active Hot List, signifying elevated community attention or exploitation activity. A public exploit exists, increasing accessibility for potential attackers. Organizations running vulnerable versions should prioritize upgrading to version 4.8.0 or later, which fully mitigates this issue. The vendor was proactively notified prior to disclosure, indicating responsible disclosure practices were followed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Lukevella | Rallly | 4.7.0, 4.7.1, 4.7.2, 4.7.3, 4.7.4CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.