CVE-2025-61873
EUVD-2026-287816.01.2026, 19:16
Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| bestpractical | request_tracker | 𝑥 < 4.4.9 | CNA |
| bestpractical | request_tracker | 5.0 ≤ 𝑥 < 5.0.9 | CNA |
| bestpractical | request_tracker | 6.0 ≤ 𝑥 < 6.0.2 | CNA |
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| request-tracker4 |
| ||||||||||||
| request-tracker5 |
|
Ubuntu Releases