CVE-2021-22911 is an improper input sanitization vulnerability in Rocket.Chat server versions 3.11, 3.12, and 3.13. The vulnerability allows unauthenticated attackers to perform NoSQL injection attacks due to insufficient sanitization of user-supplied input. This can potentially be leveraged to achieve remote code execution (RCE) on the affected server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small standalone Python exploit for Rocket.Chat CVE-2021-22911. It contains one executable code file (rocket_chat_exploit.py), a README with usage and technical notes, plus license and gitignore files. The exploit is not part of a larger framework. The script performs a full unauthenticated-to-RCE attack chain in three phases. First, it sends an anonymous forgot-password request for a known low-privilege user, then abuses a blind NoSQL injection in the getPasswordPolicy method using a $regex prefix match to recover the 43-character reset token one character at a time. It resets that user’s password to a hardcoded value. Second, it repeats the same process for the administrator account and resets the admin password to the same hardcoded value. Third, it logs in as the administrator through Rocket.Chat’s anonymous method.callAnon login API, extracts the returned user ID and auth token from the response, and uses those credentials to create an incoming webhook integration with script execution enabled. The malicious integration script is JavaScript intended for Rocket.Chat’s integration engine. It obtains access to Node.js require() via console.log.constructor('return process.mainModule.require')(), imports child_process.exec, and runs a bash reverse shell using /dev/tcp to connect back to the attacker-supplied IP and port. The exploit then triggers the generated webhook URL with an HTTP GET request, causing code execution on the target. Notable characteristics: the exploit disables TLS verification, uses hardcoded replacement password P@$$w0rd!1234, assumes the existence of both a low-privilege and admin email address, and requires outbound connectivity from the target to the attacker listener. The repository is clearly a real exploit rather than a detector, and its capabilities extend from account takeover to authenticated remote code execution.
This repository is a small standalone Python exploit for CVE-2021-22911 against Rocket.Chat, with 3 files total: a README, the main exploit script pwn_rocketchat.py, and a misspelled dependency file requiremnts.txt listing requests. The exploit is not part of a larger framework. The main script implements a full attack chain rather than a simple detector. It authenticates to the target as a normal user using Rocket.Chat's DDP-over-HTTP method endpoint, then abuses a NoSQL injection in the users.list API query parameter by supplying a crafted $where JavaScript expression that throws sensitive field values from the targeted admin user record. It first leaks services.totp.secret, then triggers a password reset for the admin email, then leaks services.password.reset.token the same way. Using the leaked TOTP secret, the script locally generates valid 6-digit TOTP codes and submits a resetPassword DDP call to set the admin password to a hardcoded value (Exp10it@2024!). After account takeover, the script logs in as the admin and abuses the integrations.create API to create an incoming webhook with scriptEnabled set to true. The embedded script uses Node.js process.mainModule.require('child_process') and cp.exec(...) to execute a base64-decoded attacker command under bash. Finally, it triggers the webhook via /hooks/{id}/{token}, causing server-side command execution. The README demonstrates using this for a reverse shell. Repository structure is straightforward: README.md documents prerequisites, arguments, and the exploitation flow; pwn_rocketchat.py contains all exploit logic including TOTP generation, DDP helper functions, NoSQL injection, password reset, and RCE via webhook; requiremnts.txt contains the single dependency. Overall, this is an operational end-to-end RCE exploit for vulnerable Rocket.Chat instances, requiring a reachable target, a valid low-privileged account, and knowledge of the admin username/email.
Repository contains a single Python exploit script (pwn_rocketchat.py) plus a README and a minimal requirements file. The exploit targets CVE-2021-22911 in Rocket.Chat <= 3.12.1 and implements a full pre-auth/low-auth chain: (1) authenticate as an existing low-priv user via Rocket.Chat’s DDP method.callAnon endpoint, (2) exploit a NoSQL injection against /api/v1/users.list using an encoded $where JavaScript expression that throws the value of a chosen field to leak sensitive admin data, specifically services.totp.secret and services.password.reset.token, (3) trigger a password reset email via sendForgotPasswordEmail, (4) reset the admin password via resetPassword while supplying a valid TOTP code computed locally from the leaked secret (bypassing 2FA), and (5) achieve RCE by logging in as admin and creating an incoming webhook integration with scriptEnabled=true containing a Node.js payload that base64-decodes and executes an attacker-provided command through child_process.exec. The script then triggers the webhook at /hooks/<id>/<token> to execute the payload. The README documents typical usage with a reverse shell command and a netcat listener on port 4444.
Repository contains a single Python exploit script (exploit.py) plus a README and .gitignore. Purpose: Automate an account takeover against Rocket.Chat (and similar Meteor-based apps) by chaining (1) authenticated access to the REST API, (2) NoSQL injection using a `$where` JavaScript clause in the `/api/v1/users.list` endpoint to force an exception that leaks the victim’s password reset token, and (3) a password reset using the leaked token via `/api/v1/method.callAnon/resetPassword`. Key flow in exploit.py: - `get_session(base_url, user_input, password)`: POSTs to `/api/v1/login` using SHA-256 digest format expected by Rocket.Chat, returning `authToken` and `userId`. - `run_exploit(args)`: Builds auth headers (`X-Auth-Token`, `X-User-Id`), sends a GET to `/api/v1/users.list` with a crafted `query` parameter containing `$where` that executes an IIFE and `throw`s `this.services.password.reset.token`. It then parses the response for `uncaught exception: <token>` and uses that token in a POST to `/api/v1/method.callAnon/resetPassword` to set a new password for the targeted user. Notable implementation details: - Disables TLS verification (`verify=False`) and suppresses urllib3 warnings (lab-style behavior). - Requires valid credentials for an initial user login; the reset step uses the anonymous method endpoint but still includes the same headers. - No CVE is referenced in the repository content; targeting is described generically as Rocket.Chat/Meteor NoSQLi via `$where`.
This repository contains a single Python exploit script (50108.py) and a README.md. The exploit targets Rocket.Chat version 3.12.1 (CVE-2021-22911), leveraging an authenticated NoSQL injection vulnerability to escalate privileges from a low-privilege user to administrator and ultimately achieve remote code execution (RCE) on the server. The attack flow is as follows: 1. The attacker authenticates as a low-privilege user (credentials required, no 2FA). 2. The script exploits NoSQL injection to extract the admin's password reset token and 2FA secret. 3. The admin password is reset using the extracted token and a generated 2FA code. 4. The attacker authenticates as admin and creates a malicious integration (webhook) with a script that executes arbitrary system commands using Node.js's child_process.exec. 5. The attacker triggers the integration to execute arbitrary commands, achieving RCE. The script interacts with several Rocket.Chat API endpoints, including those for password reset, login, user listing, integration creation, and webhook triggering. The exploit is operational and provides an interactive shell for the attacker to execute commands on the target server. The README provides setup and usage instructions, including required dependencies (requests, oathtool).
This repository contains a fully operational exploit for Rocket.Chat 3.12.1 (CVE-2021-22911), enabling unauthenticated account takeover and remote code execution (RCE). The main file, 'exploit.py', is a Python script that automates the exploitation process. It first attempts to create or take over a user account via unauthenticated NoSQL injection, then escalates privileges to an admin account (if provided), and finally achieves RCE by creating a malicious integration that executes a reverse shell to the attacker's machine. The exploit interacts with several Rocket.Chat API endpoints, leveraging unauthenticated access and NoSQL injection vulnerabilities. The payload is a bash reverse shell, and the script requires the attacker to provide a listener IP and port. The repository also includes a README.md with usage notes and a requirements.txt listing dependencies. The exploit is operational and demonstrates a full attack chain from initial access to RCE.
This repository contains a fully functional exploit for CVE-2021-22911, targeting Rocket.Chat version 3.12.1. The exploit chain leverages unauthenticated blind NoSQL injection in the getPasswordPolicy endpoint to extract password reset tokens, allowing account takeover of a low-privileged user. It then escalates privileges to the admin account by extracting the admin's 2FA secret and reset token via authenticated NoSQL injection in the users.list endpoint. Once admin access is obtained, the exploit abuses the integrations feature to achieve remote code execution (RCE) by creating a malicious webhook with a script that executes arbitrary system commands. The repository includes three Python scripts: 'exp_functions.py' (helper functions), 'exploit.py' (main exploit script), and 'new_exploit.py' (an alternative exploit script with similar logic). The exploit is operational and automates the full attack chain from initial access to RCE. Multiple Rocket.Chat API endpoints are targeted, and the attack is performed over the network. The exploit requires knowledge of user and admin emails and works against Rocket.Chat 3.12.1 with default security features enabled.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.