A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.
CVE-2021-22911
Score elevated to 9.8 because EPSS predicts 92% probability of exploitation within the next 30 days (top 0.3% of all CVEs). NVD baseline CVSS 9.8 retained for reference. Confidence: see factors.
- High exploitation likelihood — EPSS 95%
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.8
- EG Score
- 9.8(high)
- EPSS
- 99.9%
- KEV
- Not listed
Published
May 27, 2021
Last Modified
November 21, 2024
Advisory Details (2)
Auto-updated May 26, 2026NoSQL Injections in Rocket.Chat 3.12.1: How A Small Leak Grounds A Rocket | Sonar
https://blog.sonarsource.com/nosql-injections-in-rocket-chatWeakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 2× in last 7d / 13× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-18 19:29 UTCOSV refresh
- 2026-07-15 01:57 UTCEPSS rescore
- 2026-07-13 06:10 UTCEPSS rescore
- 2026-07-13 06:10 UTCEPSS rescore
- 2026-07-12 05:44 UTCEPSS rescore
- 2026-07-12 05:44 UTCEPSS rescore
- 2026-07-08 15:12 UTCEPSS rescore
- 2026-07-01 15:03 UTCEPSS rescore
- 2026-07-01 02:48 UTCOSV refresh
- 2026-06-24 14:03 UTCEPSS rescore
- 2026-06-24 14:03 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-17 17:51 UTCEPSS rescore
- 2026-06-15 17:46 UTCEPSS rescore
- 2026-06-13 22:58 UTCEPSS rescore
- 2026-06-13 04:43 UTCOSV refresh
- 2026-06-12 23:10 UTCEPSS rescore
- 2026-06-12 23:10 UTCEPSS rescore
- 2026-06-10 22:16 UTCEPSS rescore
- 2026-06-10 22:16 UTCEPSS rescore
- 2026-06-10 13:20 UTCEPSS rescore
- 2026-06-08 14:15 UTCEPSS rescore
- 2026-06-08 14:15 UTCEPSS rescore
- 2026-06-01 13:50 UTCEPSS rescore
Show 9 moreShow fewer
- 2026-06-01 13:50 UTCEPSS rescore
- 2026-05-29 13:42 UTCEPSS rescore
- 2026-05-28 13:43 UTCEPSS rescore
- 2026-05-28 13:43 UTCEPSS rescore
- 2026-05-26 16:00 UTCEG score recompute
- 2026-05-26 16:00 UTCGHSA enrichment
- 2026-05-26 07:17 UTCEPSS rescore
- 2026-05-26 07:17 UTCEPSS rescore
- 2026-05-25 07:07 UTCOSV refresh
Publicly available exploits
(6 references)Working exploit code is in the public domain (3 GitHub PoCs) (2 Exploit-DB entries). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- Open source ↗GitHub PoCFaridi-m/CVE-2021-22911-RocketChatFirst seen Mar 4, 2026
- GitHub PoCoptionalCTF/Rocket.Chat-Automated-Account-Takeover-RCE-CVE-2021-22911First seen Jul 30, 2021
Full unauthenticated RCE proof of concept for Rocket.Chat 3.12.1 CVE-2021-22911
Open source ↗ - Exploit-DBEDB-50108✓ verifiedFirst seen Jul 7, 2021
Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated) (2)
Open source ↗ - Exploit-DBEDB-49960✓ verifiedFirst seen Jun 7, 2021
Rocket.Chat 3.12.1 - NoSQL Injection (Unauthenticated)
Open source ↗ - GitHub PoCCsEnox/CVE-2021-22911First seen Jun 5, 2021
Pre-Auth Blind NoSQL Injection leading to Remote Code Execution in Rocket Chat 3.12.1
Open source ↗ - Nucleihttp/cves/2021/CVE-2021-22911.yamlFirst seen Jan 1, 2021
Rocket.Chat <=3.13 - NoSQL Injection
Open source ↗
Related CVEs(same CWE)
Same CWE
10 shownCWE-20
- CVE-2002-2444EG 9.8CRITICAL
- CVE-2005-0116NVD 0.0EG 9.0EPSS 99%NONE
- CVE-2002-1359NVD 0.0EG 9.0EPSS 100%NONE
- CVE-2000-0380NVD 0.0EG 9.0EPSS 98%NONE
- CVE-2000-0258EG 7.5EPSS 97%HIGH
- CVE-2004-2771EG 0.0EPSS 93%NONE
- CVE-2002-2443EG 0.0EPSS 93%NONE
- CVE-2002-2433EG 0.0NONE
- CVE-2003-1569EG 0.0NONE
- CVE-2003-1568EG 0.0NONE
Frequently asked(5)
What is CVE-2021-22911?
When was CVE-2021-22911 disclosed?
Is CVE-2021-22911 actively exploited?
What is the CVSS score of CVE-2021-22911?
How do I remediate CVE-2021-22911?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2021-22911
Is Your Infrastructure Affected by CVE-2021-22911?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.