Junglewise Threat Intelligence

CVE-2026-22560: Rocket.Chat open redirect in SAML SLO endpoint

CVE-2026-22560 · Severity: medium · CVSS 5.3 · Published 2026-04-10

Technologies: Rocket.Chat. Vendors: Rocket.Chat.

Executive brief

Rocket.Chat is a communication platform used for team collaboration and messaging. A security flaw in its login integration system allows attackers to redirect users to malicious external websites. This could be used in phishing campaigns to trick employees into providing credentials or downloading malware by making a malicious link appear to be a legitimate part of the company's chat service.

Technical details

An open redirect vulnerability (CWE-601) exists in Rocket.Chat's SAML Single Logout (SLO) implementation. The 'processSLORedirectAction' function failed to validate the 'redirect' query parameter, allowing unauthenticated remote attackers to craft URLs that redirect users to arbitrary external domains. The vulnerability is specifically located at the '/_saml/sloRedirect/' endpoint. Attackers can exploit this by appending a malicious URL to the redirect parameter. The fix, introduced in version 8.4.0, implements strict origin and pathname matching against the configured Identity Provider (IdP) SLO service endpoint to ensure redirects only occur to authorized destinations.

Affected products

  • Rocket.Chat Rocket.Chat < 8.4.0

Timeline

  • 2026-02-24: other: Fix proposed in GitHub pull request
  • 2026-03-26: patched: Fix merged into development branch
  • 2026-04-10: disclosed: Initial disclosure via HackerOne and NVD

References

Related threats