CVE-2026-47733
MEDIUMCVSS v3.1: 4.4 · EPSS: 0.0012 (2.0 percentile)
Source data as of:
At a glance
- Severity
- MEDIUM
- CVSS
- 4.4 v3.1 · NVD
- EPSS
- 0.0012 (2.0 percentile) · FIRST.org
- CISA KEV
- No
- Type
- XSS · NVD CWE
- Attack conditions (CVSS vector)
- Network · Source: NVD Vector
- Published
- 2026-06-24 · Modified: 2026-06-25
- References
- Jump to references (1)
CVSS / EPSS / KEV
Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources
Description
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, the ImageElement component in packages/gazzodown renders user-controlled src values directly into <a href> and <img src> attributes without protocol sanitization. Unlike the analogous LinkSpan component — which uses sanitizeUrl to block javascript:, data:, and vbscript: protocols — ImageElement passes the raw URL through unchanged. An authenticated user can post a markdown image with a javascript: URL that, if clicked on an older browser, would execute arbitrary JavaScript in the viewer's session. This vulnerability is fixed in 8.5.0.
References
Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.