CVE-2026-92565
Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from public invite links to retrieve sensitive invitee information regardless of privacy settings.
Debolezza
Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from public invite links to retrieve sensitive invitee information regardless of privacy settings.
Riferimenti
- https://github.com/lukevella/rallly
- https://github.com/lukevella/rallly/blob/885bfaf4313f427a60c5349646c5b69d863750db/apps/web/src/trpc/routers/polls.ts#L568-L675
- https://github.com/lukevella/rallly/commit/0db11a2cd9e48656d08773e4be6de0e7df584a00
- https://github.com/lukevella/rallly/pull/3247
- https://github.com/lukevella/rallly/releases/tag/v4.15.0
- https://www.vulncheck.com/advisories/rallly-before-4.15.0-information-disclosure-via-polls-get
Trova il bug prima di un attaccante.
Accedi con GitHub e avvia il tuo primo audit in meno di un minuto. Il piano gratuito non richiede carta di credito.