August 23, 2026
- Rocket.Chat disclosed two issues via HackerOne: a NoSQL injection in the Meteor DDP methods
getThreadsList/getThreadMessages(CVE-2026-65645) that lets a low-privileged authenticated user read private thread content — the REST endpoints were fixed but the DDP path was not (HackerOne) — and an unauthenticated stored HTML injection viaPOST /api/v1/livechat/visitorthat yields DOM XSS in the Omnichannel queue (HackerOne). · Vulnerabilities & Exploits
in A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick