Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Visitor Name Injection Enables XSS in Rocket.Chat Livechat Queue | |
| First Time appeared |
Rocket.chat
Rocket.chat rocket.chat |
|
| Vendors & Products |
Rocket.chat
Rocket.chat rocket.chat |
Fri, 21 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue. | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-08-21T02:53:43.406Z
Reserved: 2026-07-22T15:00:06.103Z
Link: CVE-2026-65644
No data.
Status : Received
Published: 2026-08-21T04:18:13.780
Modified: 2026-08-21T04:18:13.780
Link: CVE-2026-65644
No data.
OpenCVE Enrichment
Updated: 2026-08-21T04:30:09Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')