{"id":"CVE-2026-65644","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-65644","summary":null,"details":"Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue.","published":"2026-08-21T02:53:43.406Z","modified":"2026-08-23T03:49:46.185167775Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/RocketChat/Rocket.Chat/pull/41595","label":"RocketChat/Rocket.Chat#41595"},"references":[{"type":"WEB","url":"https://hackerone.com/reports/3872858"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65644.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65644"},{"type":"FIX","url":"https://github.com/RocketChat/Rocket.Chat/pull/41595"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-23T03:49:46.185167775Z"}}