CVE-2024-45621: Rocket.chat

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.

Affected products

Published 2024-09-02. Last modified 2026-06-17.