GHSA-36pr-h5jw-r82mMediumCVSS 5.3
Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC...
🔗 CVE IDs covered (1)
📋 Description
Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from public invite links to retrieve sensitive invitee information regardless of privacy settings.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-92565
- https://github.com/lukevella/rallly/pull/3247
- https://github.com/lukevella/rallly/commit/0db11a2cd9e48656d08773e4be6de0e7df584a00
- https://github.com/lukevella/rallly
- https://github.com/lukevella/rallly/blob/885bfaf4313f427a60c5349646c5b69d863750db/apps/web/src/trpc/routers/polls.ts#L568-L675
- https://github.com/lukevella/rallly/releases/tag/v4.15.0
- https://www.vulncheck.com/advisories/rallly-before-4.15.0-information-disclosure-via-polls-get
- https://github.com/advisories/GHSA-36pr-h5jw-r82m