CVE-2025-61873: Bestpractical Request Tracker
Low severity, CVSS 2.6. EPSS: 0.2% chance of exploitation in the next 30 days.
Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.
Affected products
- Bestpractical Request Tracker: before 4.4.9 (fixed in 4.4.9); from 5.0, before 5.0.9 (fixed in 5.0.9); from 6.0, before 6.0.2 (fixed in 6.0.2)
Published 2026-01-16. Last modified 2026-06-17.