7.5

CVE-2026-65644

Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rocket.Chat ≫ Rocket.Chat Version < 7.10.15
Rocket.Chat ≫ Rocket.Chat Version >= 8.1.0 < 8.1.8
Rocket.Chat ≫ Rocket.Chat Version >= 8.2.0 < 8.2.8
Rocket.Chat ≫ Rocket.Chat Version >= 8.3.0 < 8.3.8
Rocket.Chat ≫ Rocket.Chat Version >= 8.4.0 < 8.4.6
Rocket.Chat ≫ Rocket.Chat Version >= 8.5.0 < 8.5.3
Rocket.Chat ≫ Rocket.Chat Version >= 8.6.0 < 8.6.2
Rocket.Chat ≫ Rocket.Chat Version 8.7.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://hackerone.com/reports/3872858
Third Party Advisory
Issue Tracking
https://github.com/RocketChat/Rocket.Chat/pull/41595
Patch
Vendor Advisory