CVE-2025-47781
Last modified
CVE-2025-47781 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Rallly is an open-source scheduling and collaboration tool. Versions up to and including 3.22.1 of the application features token based authentication. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
Rallly is an open-source scheduling and collaboration tool. Versions up to and including 3.22.1 of the application features token based authentication. When a user attempts to login to the application, they insert their email and a 6 digit code is sent to their email address to complete the authentication. A token that consists of 6 digits only presents weak entropy however and when coupled with no token brute force protection, makes it possible for an unauthenticated attacker with knowledge of a valid email address to successfully brute force the token within 15 minutes (token expiration time) and take over the account associated with the targeted email address. All users on the Rallly applications are impacted. As long as an attacker knows the user's email address they used to register on the app, they can systematically take over any user account. For the authentication mechanism to be safe, the token would need to be assigned a complex high entropy value that cannot be bruteforced within reasonable time, and ideally rate limiting the /api/auth/callback/email endpoint to further make brute force attempts unreasonable within the 15 minutes time. As of time of publication, no patched versions are available.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rallly | Rallly | <= 3.11.2 |
References
- https://github.com/lukevella/rallly/security/advisories/GHSA-gm8g-3r3j-48hvExploit, Vendor Advisory
- https://github.com/lukevella/rallly/security/advisories/GHSA-gm8g-3r3j-48hvExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-47781?
How severe is CVE-2025-47781?
How do I fix CVE-2025-47781?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-47776Mantis Bug Tracker (MantisBT) is an open source issue tracke…9.1
- CVE-2025-477775ire is a cross-platform desktop artificial intelligence ass…9.6
- CVE-2025-47778Sulu is an open-source PHP content management system based o…6.1
- CVE-2025-47779Asterisk is an open-source private branch exchange (PBX). Pr…6.5
- CVE-2025-4778A vulnerability was found in PHPGurukul Park Ticketing Manag…8.8
- CVE-2025-47780Asterisk is an open-source private branch exchange (PBX). Pr…7.8
- CVE-2025-47782motionEye is an online interface for the software motion, a …8.9
- CVE-2025-47783Label Studio is a multi-type data labeling and annotation to…6.1
- CVE-2025-47784Emlog is an open source website building system. Versions 2.…9.8
- CVE-2025-47785Emlog is an open source website building system. In versions…8.8
- CVE-2025-47786Emlog is an open source website building system. Version 2.5…4.8
- CVE-2025-47787Emlog is an open source website building system. Emlog Pro p…9.8
Are you affected by CVE-2025-47781?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
