Security Flaw in Rocket.Chat Affecting Livechat Visitors
CVE-2026-65644
Currently unrated
What is CVE-2026-65644?
Rocket.Chat versions prior to 8.8.0 contain a significant vulnerability within its Livechat feature. The REST API endpoint POST /api/v1/livechat/visitor allows unauthenticated users to submit a name field that is not properly sanitized. This input is stored in its raw form and later rendered in the Omnichannel Queue panel, allowing an attacker to inject malicious HTML content. Consequently, this can lead to the display of clickable links to attacker-controlled domains with deceptive text, exposing agents to social engineering attacks and potential phishing attempts.
Affected Version(s)
Rocket.Chat 0 < 8.8.0
Rocket.Chat 0 < 8.7.1
Rocket.Chat 0 < 8.6.2
