Executive brief
Rocket.Chat is an open-source communications platform used for team collaboration and messaging. A security flaw in how the platform handles images in messages allows a malicious user to embed hidden scripts within an image link. If a victim using an older web browser clicks on such an image, the script could execute in their session, potentially allowing the attacker to access sensitive information or perform actions on the victim's behalf.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in Rocket.Chat's 'gazzodown' package due to missing protocol sanitization in the ImageElement component. While the analogous LinkSpan component uses a 'sanitizeUrl' function to block dangerous protocols like 'javascript:', 'data:', and 'vbscript:', ImageElement renders user-controlled 'src' values directly into <a> href and <img> src attributes. An authenticated attacker can post a markdown image containing a 'javascript:' URI. While modern browsers typically block JavaScript execution when navigation occurs via target='_blank', users on legacy browsers remain vulnerable to arbitrary script execution in their session context upon clicking the image. This issue is resolved in version 8.5.0 by applying the 'sanitizeUrl' utility to the ImageElement component.
Affected products
- RocketChat Rocket.Chat < 8.5.0
Timeline
- 2026-06-11: advisory: GitHub advisory published by vendor
- 2026-06-24: disclosed: NVD publication date
- 2026-08-05: patched: Fixed in version 8.5.0