CVE-2021-22911

CRITICAL EXPLOITED NUCLEI

Rocket.Chat 3.11-3.13 - Unauthenticated NoSQL Injection and Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-22911 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 15 public exploits from researchers including enox, CsEnox, optionalCTF. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit leverages a NoSQL injection vulnerability in Rocket.Chat to reset passwords, bypass authentication, and achieve remote code execution via integration creation. It automates the process of retrieving reset tokens and 2FA secrets to escalate privileges to administrator.

Description

A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.

Exploits (15)

exploitdb WORKING POC VERIFIED
by enox · pythonwebappslinux
https://www.exploit-db.com/exploits/50108

This exploit leverages a NoSQL injection vulnerability in Rocket.Chat to reset passwords, bypass authentication, and achieve remote code execution via integration creation. It automates the process of retrieving reset tokens and 2FA secrets to escalate privileges to administrator.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Rocket.Chat 3.12.1
No auth needed
Prerequisites: Low-privileged user email without 2FA · Administrator email · Target URL
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by enox · pythonwebappslinux
https://www.exploit-db.com/exploits/49960

This exploit demonstrates a NoSQL injection vulnerability in Rocket.Chat 3.12.1, leading to unauthenticated remote code execution (RCE) by chaining password reset token brute-forcing, privilege escalation via 2FA bypass, and integration-based command execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Rocket.Chat 3.12.1
No auth needed
Prerequisites: Target Rocket.Chat instance · Email addresses of a low-privilege user and an admin · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 59 stars
by CsEnox · remote-auth
https://github.com/CsEnox/CVE-2021-22911

This repository contains a functional exploit for CVE-2021-22911, demonstrating a pre-auth blind NoSQL injection in Rocket.Chat 3.12.1 leading to RCE. The exploit chains account hijacking, privilege escalation via 2FA secret retrieval, and RCE through webhook script execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Rocket.Chat 3.12.1
No auth needed
Prerequisites: Knowledge of a low-privilege user's email without 2FA · Administrator email address · Password policy enabled · 2FA enabled for admin (optional)
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 9 stars
by optionalCTF · poc
https://github.com/optionalCTF/Rocket.Chat-Automated-Account-Takeover-RCE-CVE-2021-22911

This repository contains a functional exploit for CVE-2021-22911, demonstrating unauthenticated NoSQL injection leading to account takeover and RCE in Rocket.Chat 3.12.1. The exploit automates user creation, password reset token extraction via NoSQLi, and RCE via integration hooks.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Rocket.Chat 3.12.1
No auth needed
Prerequisites: Target Rocket.Chat instance running version 3.12.1 · Network access to the target · Listener setup for reverse shell
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by roshanrajbanshi · remote
https://github.com/roshanrajbanshi/rocketcat-cve-2021-22911-exploit

This repository contains a functional exploit for CVE-2021-22911, a critical unauthenticated NoSQL injection vulnerability in Rocket.Chat leading to Remote Code Execution (RCE). The exploit chains three phases: password reset for a low-privilege user, admin password reset via blind NoSQL injection, and RCE through a malicious webhook integration.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Rocket.Chat < 3.12.7
No auth needed
Prerequisites: pip install requests · Netcat listener for reverse shell
devstral-2 · analyzed Apr 10, 2026 Full analysis →
nomisec WORKING POC
by Faridi-m · poc
https://github.com/Faridi-m/CVE-2021-22911-RocketChat

This repository contains a functional exploit for CVE-2021-22911, which targets a NoSQL injection vulnerability in Rocket.Chat 3.12.1. The exploit chains authentication bypass, TOTP secret leakage, admin account takeover, and remote code execution via a malicious webhook integration.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Rocket.Chat <= 3.12.1
Auth required
Prerequisites: low-privilege user credentials · admin email address · admin username · network access to target
devstral-2 · analyzed Apr 10, 2026 Full analysis →
nomisec WORKING POC
by Faridi-m · remote-auth
https://github.com/Faridi-m/CVE-2021-22911-RocketChat-Improvised-

This repository contains a functional exploit for CVE-2021-22911, targeting Rocket.Chat <= 3.12.1. It leverages a NoSQL injection vulnerability to leak admin TOTP secrets and password reset tokens, then achieves RCE via a malicious webhook integration.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Rocket.Chat <= 3.12.1
Auth required
Prerequisites: low-privilege user credentials · admin email address · admin username · network access to target
devstral-2 · analyzed Mar 05, 2026 Full analysis →
nomisec WORKING POC
by TeneBrae93 · remote
https://github.com/TeneBrae93/RocketChat-NoSQLi-Chain-CVE-2021-22911

This repository contains a functional exploit for CVE-2021-22911, a NoSQL injection vulnerability in Rocket.Chat. The exploit leverages a `$where` clause to leak password reset tokens via server-side exceptions and then resets the target user's password.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Rocket.Chat (and Meteor-based applications)
Auth required
Prerequisites: Valid user credentials for initial authentication · Target admin username · Access to the Rocket.Chat API endpoints
devstral-2 · analyzed Feb 26, 2026 Full analysis →
nomisec WORKING POC
by octodi · remote-auth
https://github.com/octodi/CVE-2021-22911

This repository contains a functional exploit for CVE-2021-22911, which leverages NoSQL injection in Rocket.Chat 3.12.1 to achieve unauthenticated remote code execution (RCE). The exploit chain includes password reset token extraction, privilege escalation to admin, and RCE via integration creation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Rocket.Chat 3.12.1
No auth needed
Prerequisites: Low-privileged user email (without 2FA) · Administrator email · Target URL
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by yoohhuu · remote-auth
https://github.com/yoohhuu/Rocket-Chat-3.12.1-PoC-CVE-2021-22911-

This repository contains a functional exploit for CVE-2021-22911, a NoSQL injection vulnerability in Rocket.Chat 3.12.1 that leads to unauthenticated RCE. The exploit chains password reset token extraction, authentication bypass, and integration-based command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Rocket.Chat 3.12.1
No auth needed
Prerequisites: Target Rocket.Chat instance · Administrator email address · Low-privilege user email address
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by overgrowncarrot1 · remote
https://github.com/overgrowncarrot1/CVE-2021-22911

This repository contains a functional exploit for CVE-2021-22911, which targets RocketChat 3.12.1. The exploit resets the admin password via a NoSQL injection and then achieves RCE by creating a malicious integration with a reverse shell payload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: RocketChat 3.12.1
No auth needed
Prerequisites: A low-privileged user email without 2FA · Administrator email · Target URL · Attacker IP and port for reverse shell
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by MrDottt · remote
https://github.com/MrDottt/CVE-2021-22911

This repository contains a functional exploit for CVE-2021-22911, demonstrating a pre-auth blind NoSQL injection in Rocket.Chat 3.12.1 leading to RCE. The exploit chains account hijacking, privilege escalation via 2FA secret extraction, and RCE through webhook script execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Rocket.Chat 3.12.1
No auth needed
Prerequisites: Low-privilege user email without 2FA · Administrator email
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by ChrisPritchard · remote
https://github.com/ChrisPritchard/CVE-2021-22911-rust

This repository contains a functional Rust exploit for CVE-2021-22911, targeting Rocket.Chat's password reset mechanism to achieve remote code execution (RCE) via webhook manipulation. The exploit automates password reset, token brute-forcing, and command execution through crafted webhooks.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Rocket.Chat (version not specified, but likely pre-patch for CVE-2021-22911)
No auth needed
Prerequisites: Admin email address · Admin username · MFA disabled · Network access to target
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by jayngng · poc
https://github.com/jayngng/CVE-2021-22911

This repository contains a functional exploit for CVE-2021-22911, a NoSQL injection vulnerability in Rocket.Chat 3.12.1 that leads to remote code execution (RCE). The exploit chain involves password reset token leakage, privilege escalation to admin, and RCE via integration creation.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Rocket.Chat 3.12.1
Auth required
Prerequisites: Valid credentials for a low-privileged user · Administrator email address · Target URL
devstral-2 · analyzed Feb 18, 2026 Full analysis →
vulncheck_xdb WORKING POC
remote
https://github.com/Walker-00/wisad

This repository contains a functional exploit for CVE-2021-22911, targeting a password reset vulnerability in Rocket.Chat. The script automates the process of resetting passwords for both user and admin accounts by exploiting a token leakage flaw.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Rocket.Chat (versions affected by CVE-2021-22911)
No auth needed
Prerequisites: target URL · user email/name · admin email/name
devstral-2 · analyzed Feb 25, 2026 Full analysis →

Nuclei Templates (1)

Rocket.Chat <=3.13 - NoSQL Injection
CRITICALVERIFIEDby tess,sullo
Shodan: http.title:"Rocket.Chat" || http.title:"rocket.chat"
FOFA: title="rocket.chat"

References (4)

Core 4
Core References
Exploit, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1130721
Exploit, Third Party Advisory x_refsource_misc
https://blog.sonarsource.com/nosql-injections-in-rocket-chat

Scores

CVSS v3 9.8
EPSS 0.9182
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-11-14
CWE
CWE-75
Status published
Products (3)
rocket.chat/rocket.chat 3.11.0
rocket.chat/rocket.chat 3.12.0
rocket.chat/rocket.chat 3.13.0
Published May 27, 2021
Tracked Since Feb 18, 2026