Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6493

17
FAUCET Score

OVERVIEW CVE-2026-6493 is a cross-site scripting (XSS) vulnerability affecting lukevella rallly versions up to 4.7.4. The flaw exists in the Reset Password Handler component, specifically within the reset-password-form.tsx file, where improper validation of the redirectTo argument allows attackers to inject malicious scripts. This vulnerability has a published exploit available in the public domain. SEVERITY The vulnerability carries a CVSS v3.1 score of 3.5 (LOW) with a network-based attack vector requiring low complexity and user interaction. Attack prerequisites include valid authentication credentials. The impact is limited to integrity violations with no confidentiality or availability impact. However, the FAUCET Risk Score of 28.0/100 suggests moderate organizational risk when considering real-world exploitation factors and attack complexity. EXPLOITATION STATUS While the CVSS and EPSS scores indicate low baseline threat levels, the vulnerability is listed on the Active Hot List, signifying elevated community attention or exploitation activity. A public exploit exists, increasing accessibility for potential attackers. Organizations running vulnerable versions should prioritize upgrading to version 4.8.0 or later, which fully mitigates this issue. The vendor was proactively notified prior to disclosure, indicating responsible disclosure practices were followed.

Impacted Technologies

VendorProductVersion(s)CPE
LukevellaRallly
4.7.0, 4.7.1, 4.7.2, 4.7.3, 4.7.4CNA affected

CVSS Data

CVSS version used by this source: 4.0

2.0LOW

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 47th percentile among its peer group of 406 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

gist.github.com / TrebledJ/0bd0494a28daaa16abb565b2cef4bd7c
github.com / lukevella/rallly
github.com / lukevella/rallly/pull/2245
github.com / lukevella/rallly/releases/tag/v4.8.0
vuldb.com / submit/787347
vuldb.com / vuln/358037
vuldb.com / vuln/358037/cti