CVE-2026-65644

HIGH CVSS 3.1: 7.5 EPSS 0.29%
Updated Sep 04, 2026
Rocket.Chat
Parameter Value
CVSS 7.5 (HIGH)
Affected Versions 8.1.0 — 8.6.2
Fixed In 7.10.15
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Rocket.Chat
Public PoC No

Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 8

Configuration From (including) Up to (excluding)
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
7.10.15
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
8.1.0 8.1.8
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
8.2.0 8.2.8
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
8.3.0 8.3.8
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
8.4.0 8.4.6
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
8.5.0 8.5.3
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
8.6.0 8.6.2
Rocket.Chat Rocket.Chat
cpe:2.3:a:rocket.chat:rocket.chat:8.7.0:*:*:*:*:*:*:*