Best Practical Request Tracker CSV Injection Vulnerability

Vulnerability

A CSV injection vulnerability has been identified in Best Practical Request Tracker (RT) versions prior to 4.4.9, 5.0.9, and 6.0.2. This vulnerability allows malicious users to inject CSV-formatted data into ticket values, which can be exploited when the data is exported in TSV format.

Impact

Exploitation of this vulnerability could lead to CSV injection, where exported data is manipulated to execute unintended commands or scripts when opened in a spreadsheet application.

Added: Jan 16, 2026, 7:22 PM
Updated: Jan 16, 2026, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
4.6
remediation
7.7
relevance
2.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.