CyberRota Analysis
AI-GeneratedRocket.Chat versions prior to 8.8.0 are vulnerable due to an unauthenticated REST API endpoint that allows attackers to inject arbitrary HTML links into the Omnichannel Queue side panel. This flaw can lead to social engineering attacks, as agents may unknowingly click on malicious links that direct them to attacker-controlled domains. Organizations using affected Rocket.Chat versions, especially those with live chat functionalities, should prioritize patching to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)