Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message. This flaw leads to arbitrary file read and RCE on Rocket.Chat desktop app.
| Software | From | Fixed in |
|---|---|---|
| rocket.chat / rocket.chat | 3.11.0-rc0 | 3.11.0-rc0.x |
| rocket.chat / rocket.chat | 3.11.0-rc1 | 3.11.0-rc1.x |
| rocket.chat / rocket.chat | 3.11.0-rc2 | 3.11.0-rc2.x |
| rocket.chat / rocket.chat | 3.11.0-rc3 | 3.11.0-rc3.x |
| rocket.chat / rocket.chat | 3.11.0-rc4 | 3.11.0-rc4.x |
| rocket.chat / rocket.chat | 3.11.0-rc5 | 3.11.0-rc5.x |
| rocket.chat / rocket.chat | 3.11.0-rc6 | 3.11.0-rc6.x |
| rocket.chat / rocket.chat | 3.11.0-rc7 | 3.11.0-rc7.x |
| rocket.chat / rocket.chat | 3.10.0 | 3.10.5 |
| rocket.chat / rocket.chat | 3.9.0 | 3.9.7 |
| rocket.chat / rocket.chat | - | 3.8.8 |