Rocket.Chat

Rocket.Chat

63 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.72%
  • Veröffentlicht 16.06.2026 23:08:37
  • Zuletzt bearbeitet 16.06.2026 23:08:37

Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion. The deleteFileMessage Meteor method permanently deletes any uploaded file by ID without requiring authentica...

  • EPSS 0.3%
  • Veröffentlicht 16.06.2026 23:08:37
  • Zuletzt bearbeitet 16.06.2026 23:08:37

Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+r...

  • EPSS 0.28%
  • Veröffentlicht 28.05.2026 04:01:37
  • Zuletzt bearbeitet 01.06.2026 18:04:45

The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a client-supplied IMessage object and passes it directly to translateMessage() without checking Meteor...

  • EPSS 0.25%
  • Veröffentlicht 19.05.2026 04:43:41
  • Zuletzt bearbeitet 19.05.2026 14:50:07

The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any authenticated user to retrieve the full content of any message from any room (private groups, direct mess...

  • EPSS 0.18%
  • Veröffentlicht 23.04.2026 23:19:40
  • Zuletzt bearbeitet 28.04.2026 19:34:33

In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/logs and /api/apps/:id/logs have a typo in the required permission check, allowing authenticated users without the proper permissions...

  • EPSS 0.42%
  • Veröffentlicht 22.04.2026 23:30:15
  • Zuletzt bearbeitet 13.05.2026 20:39:44

In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.

  • EPSS 0.32%
  • Veröffentlicht 10.04.2026 17:00:11
  • Zuletzt bearbeitet 17.04.2026 22:01:13

An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint.

  • EPSS 0.27%
  • Veröffentlicht 06.03.2026 17:40:36
  • Zuletzt bearbeitet 13.03.2026 18:46:27

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, a NoSQL injection vulnerability exists in Rocket.Chat's account service used in the ddp-stre...

  • EPSS 0.33%
  • Veröffentlicht 06.03.2026 17:40:27
  • Zuletzt bearbeitet 13.03.2026 18:52:27

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnerabilities exist in Rocket.Chat's enterprise DDP Streamer service. The A...

  • EPSS 0.5%
  • Veröffentlicht 06.03.2026 17:35:01
  • Zuletzt bearbeitet 18.03.2026 16:10:07

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critical authentication bypass vulnerability exists in Rocket.Chat's account service used ...