---
id: CVE-2025-66027
title: Rallly is an open-source scheduling and collaboration tool
summary: >-
  Rallly is an open-source scheduling and collaboration tool. Prior to version
  4.5.6, an information disclosure vulnerability exposes participant details,
  including names and email addresses through the
  /api/trpc/polls.get,polls.participan…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
  - CWE-284
  - CWE-359
vendor: rallly
product: rallly
affected:
  - rallly < 4.5.6
patched:
  - rallly 4.5.6
published: '2025-11-29'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66027'
references:
  - url: >-
      https://github.com/lukevella/rallly/commit/59738c04f9a8ec25f0af5ce20ad0eab6cf134963
    label: security-advisories@github.com
  - url: 'https://github.com/lukevella/rallly/releases/tag/v4.5.6'
    label: security-advisories@github.com
  - url: >-
      https://github.com/lukevella/rallly/security/advisories/GHSA-65wg-8xgw-f3fg
    label: security-advisories@github.com
  - url: >-
      https://github.com/lukevella/rallly/security/advisories/GHSA-65wg-8xgw-f3fg
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00352
epssPercentile: 0.26634
ingestedAt: '2026-10-07T20:46:46.735Z'
---

## Overview

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through the /api/trpc/polls.get,polls.participants.list endpoint, even when Pro privacy features are enabled. This bypasses intended privacy controls that should prevent participants from viewing other users’ personal information. This issue has been patched in version 4.5.6.

## Affected

- `rallly < 4.5.6`

## Remediation

Upgrade past the affected range:

- `rallly 4.5.6`
