CVE-2025-65028 Overview
Rallly is an open-source scheduling and collaboration tool used to coordinate group availability through polls. CVE-2025-65028 is an Insecure Direct Object Reference (IDOR) vulnerability affecting Rallly versions prior to 4.5.4. The backend accepts a participantId parameter when updating votes but does not verify that the authenticated user owns the referenced participant record. Any authenticated user can therefore modify votes belonging to other participants in any poll. The vendor patched the flaw in version 4.5.4.
Critical Impact
Authenticated attackers can alter other users' poll votes without authorization, compromising the integrity of scheduling decisions driven by Rallly polls.
Affected Products
- Rallly versions prior to 4.5.4
- Self-hosted Rallly deployments exposing the vote update endpoint
- Managed Rallly instances that had not yet applied the 4.5.4 update
Discovery Timeline
- 2025-11-19 - CVE-2025-65028 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-65028
Vulnerability Analysis
The flaw is a classic Insecure Direct Object Reference tracked under CWE-285: Improper Authorization. Rallly's vote update handler trusts the client-supplied participantId value to select which participant record to modify. It does not cross-check that the authenticated session owns that participant, nor that the caller has permission to edit votes on the target poll.
Because polls in Rallly are the source of truth for meeting availability, unauthorized vote modification directly undermines the tool's business function. An attacker can shift outcomes, deny quorum for a proposed time slot, or forge consensus around a preferred option. Data integrity is fully compromised while confidentiality and availability remain intact, consistent with the vector's integrity-only impact.
Root Cause
The root cause is missing object-level authorization on the vote update path. The backend derives the target record solely from the request payload rather than binding the operation to the caller's identity or verifying the caller's role on the parent poll. Standard authorization checks that would tie participantId to the current session are absent.
Attack Vector
Exploitation requires only a valid authenticated Rallly account and network access to the application. An attacker enumerates or observes participantId values from a target poll and issues a vote update request substituting the victim's identifier. The server processes the request and rewrites the victim's votes. No user interaction, elevated privileges, or specialized tooling is required. See the GitHub Security Advisory GHSA-pchc-v5hg-f5gp for the vendor description.
No public proof-of-concept exploit is listed in NVD, and the vulnerability is not present on the CISA Known Exploited Vulnerabilities catalog. The current EPSS probability is 0.256%.
Detection Methods for CVE-2025-65028
Indicators of Compromise
- Vote update requests where the authenticated user's session does not correspond to the participantId in the request body.
- Unexpected changes to participant vote records without a corresponding login or edit event from the participant's own account.
- Polls whose results shift after closure or immediately before a decision, without matching user activity in application logs.
Detection Strategies
- Instrument the Rallly application (or a reverse proxy) to log the authenticated user identifier alongside every vote update request and its participantId parameter.
- Alert when the two identifiers diverge, which represents the exact abuse pattern for CVE-2025-65028.
- Compare vote change events against session activity for the owning participant to identify unattributed modifications.
Monitoring Recommendations
- Retain HTTP access logs and application audit logs for the Rallly vote endpoints for post-incident review.
- Baseline normal poll activity per user and flag accounts that modify votes across an unusually broad set of polls or participants.
- Track deployed Rallly versions across self-hosted instances to confirm all are running 4.5.4 or later.
How to Mitigate CVE-2025-65028
Immediate Actions Required
- Upgrade all Rallly deployments to version 4.5.4 or later using the Rallly v4.5.4 release notes.
- Audit recent poll activity for suspicious vote changes on polls whose outcomes influenced business decisions.
- Review authenticated user accounts and disable any that show signs of abusing the vote update endpoint.
Patch Information
The vendor fixed CVE-2025-65028 in Rallly v4.5.4. The patch adds authorization checks binding vote update operations to the caller's ownership of the referenced participant. Full details are in the GitHub Security Advisory GHSA-pchc-v5hg-f5gp.
Workarounds
- Restrict access to Rallly to trusted user populations until the upgrade is complete, since exploitation requires an authenticated account.
- Place Rallly behind a reverse proxy that logs and rate-limits requests to vote update endpoints to slow enumeration of participantId values.
- Recreate high-value polls after upgrading if their integrity cannot be verified from logs.
# Upgrade a Docker-based Rallly deployment to the patched release
docker pull lukevella/rallly:4.5.4
docker stop rallly && docker rm rallly
docker run -d --name rallly --env-file .env -p 3000:3000 lukevella/rallly:4.5.4
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
