-

CVE-2026-65644

Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRocket.Chat
Produkt Rocket.Chat
Default Statusunaffected
Version 0
Version < 8.8.0
Status affected
Version 0
Version < 8.7.1
Status affected
Version 0
Version < 8.6.2
Status affected
Version 0
Version < 8.5.3
Status affected
Version 0
Version < 8.4.6
Status affected
Version 0
Version < 8.3.8
Status affected
Version 0
Version < 8.2.8
Status affected
Version 0
Version < 8.1.8
Status affected
Version 0
Version < 7.10.15
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
Es wurden noch keine Metriken (CVSS, EPSS) zu dieser CVE veröffentlicht.
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://hackerone.com/reports/3872858
https://github.com/RocketChat/Rocket.Chat/pull/41595