Last week, the team behind Next.JS, a popular javascript framework, reported a critical vulnerability (severity 10/10), in turn affecting softwares that are built using this framework. In particular, this affects the Rallly app. This vulnerability is currently exploited in the wild, allowing attackers to, for example, install cryptominers on the server.
Rally version 4.5.8 (and upwards) includes a fix for the NextJS CVE, see upstream release notes for details.
For reference, the support thread with an impacted instance of Rallly.