Medium severity6.1NVD Advisory· Published Apr 1, 2022· Updated Jun 17, 2026
CVE-2022-21830
CVE-2022-21830
Description
A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@rocket.chat/livechatnpm | < 1.9.0 | 1.9.0 |
Affected products
3- RocketChat/LiveChatdescription
Patches
Vulnerability mechanics
References
5- hackerone.com/reports/1091118nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-hf55-c445-2w97ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-21830ghsaADVISORY
- github.com/RocketChat/Rocket.Chat.Livechat/pull/558ghsaWEB
- github.com/RocketChat/Rocket.Chat.Livechat/releases/tag/v1.9.0ghsaWEB
News mentions
0No linked articles in our index yet.