PatchSiren cyber security CVE debrief
CVE-2026-65644 Rocket.Chat CVE debrief
Rocket.Chat versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 have a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel, injecting a clickable HTML link into the DOM of any agent viewing the queue. The vulnerability allows for potential social engineering attacks through injected HTML links in the Omnichannel Queue side panel. Rocket.Chat users and administrators should prioritize patching and review compensating controls. Affected teams should verify inventory, assess potential exposure, and implement monitoring for suspicious activity. Vulnerability management and security teams should track exceptions and retest remediated assets after verification of patches or mitigations.
- Vendor
- Rocket.Chat
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-09-03
Who should care
Rocket.Chat users and administrators, security teams monitoring for social engineering attacks, and operators managing Rocket.Chat deployments should prioritize patching and review compensating controls. Affected teams should verify inventory, assess potential exposure, and implement monitoring for suspicious activity on the Omnichannel Queue side panel. Vulnerability management and security teams should track exceptions and retest remediated assets after verification of patches or mitigations. Rocket.Chat users should also review and limit use of the livechat/visitor endpoint to prevent potential social engineering attacks through injected HTML links in the Omnichannel Queue side panel. This requires coordination with IT and development teams to ensure proper configuration and security controls are in place. Additionally, defenders should be aware of potential attacker-controlled domains and arbitrary social-engineering text that could be injected into the DOM of any agent viewing the queue, emphasizing the need for careful monitoring and defense-in-depth strategies. Rocket.Chat administrators should ensure that agents viewing the queue are aware of the potential risks and take necessary precautions to avoid clicking on suspicious links. By taking these steps, Rocket.Chat users and administrators can help prevent potential social engineering attacks and protect their systems from exploitation. It is also essential to consider the potential operational impact of this vulnerability and prioritize patching and mitigation efforts accordingly. This may involve coordinating with stakeholders to ensure that affected systems are properly secured and that necessary controls are in place to prevent exploitation. Overall, a comprehensive approach to vulnerability management and security is necessary to address the potential risks associated with this CVE record. This includes ongoing monitoring, regular security assessments, and a proactive approach to identifying and mitigating potential vulnerabilities. By prioritizing patching and taking a proactive approach to security, Rocket.Chat users and administrators can help protect their systems from potential exploitation and
Technical summary
Rocket.Chat versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 have a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel, injecting a clickable HTML link into the DOM of any agent viewing the queue.
Defensive priority
Rocket.Chat users should prioritize patching to prevent potential social engineering attacks.
Recommended defensive actions
- Patch Rocket.Chat to version 8.8.0 or later
- Review and limit use of the livechat/visitor endpoint
- Monitor for suspicious activity on the Omnichannel Queue side panel
- Verify inventory of Rocket.Chat deployments
- Assess potential exposure and implement compensating controls
- Track exceptions and retest remediated assets
- Review official advisory or CVE record for specific affected versions and update guidance
Evidence notes
Evidence is limited; primary official records indicate Rocket.Chat versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 have a REST API endpoint vulnerability. Further inventory checks and vendor remediation are needed to verify potentially exposed deployments and assess operational impact. Defenders should review the official CVE record and vendor advisory for specific affected versions and update guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-65644 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-65644
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-65644 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-65644
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/RocketChat/Rocket.Chat/pull/41595
-
Source reference
Unverified legacy reference
URL: https://hackerone.com/reports/3872858
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.