← Back

CVE-2026-65644

nvd nist
Published: Aug 21, 2026Modified: Sep 4, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue.

Affected (8)

1 product
Rocket.chat
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Rocket.chat
Before 7.10.15
From 8.1.0 to 8.1.8
From 8.2.0 to 8.2.8
From 8.3.0 to 8.3.8
From 8.4.0 to 8.4.6
From 8.5.0 to 8.5.3
From 8.6.0 to 8.6.2
Version 8.7.0

References (2)

Source: support@hackerone.com
PatchVendor Advisory
Source: support@hackerone.com
Third Party AdvisoryIssue Tracking

Timeline

No history available yet.