CVE-2026-65644 | Rocket.Chat up to 7.10.14/8.7.0 Omnichannel Queue InquireSidePanelItem.tsx dangerouslySetInnerHTML Name injection (EUVD-2026-63806)

SecurityVulns

A vulnerability labeled as critical has been found in Rocket.Chat up to 7.10.14/8.7.0. The affected element is the function dangerouslySetInnerHTML of the file InquireSidePanelItem.tsx of the component Omnichannel Queue. The manipulation of the argument Name results in injection.

This vulnerability is identified as CVE-2026-65644. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More