Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

RocketChat — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting RocketChat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

RocketChat serves as an open-source team communication platform, offering real-time messaging, video conferencing, and file sharing. Historically, it has faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and access control flaws. The platform's self-hosted nature provides organizations with control over their data but requires diligent security maintenance. While no major public security incidents have been widely documented, the presence of five CVEs indicates ongoing security considerations. Users must implement regular updates and hardening measures to mitigate risks, as the platform's extensive feature set and integrations expand its potential attack surface.

Top products by RocketChat: Rocket.Chat
CVE IDTitleCVSSSeverityPublished
CVE-2026-55762 Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v1/fingerprint` Endpoint — Rocket.ChatCWE-862 8.1 High2026-06-24
CVE-2026-55759 Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay — Rocket.ChatCWE-287 7.4 High2026-06-24
CVE-2026-55666 Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth — Rocket.ChatCWE-287--2026-06-24
CVE-2026-49278 Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation — Rocket.ChatCWE-285 6.7 Medium2026-06-24
CVE-2026-49277 Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation — Rocket.ChatCWE-613--2026-06-24
CVE-2026-45757 Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens — Rocket.ChatCWE-613--2026-06-24
CVE-2026-46423 Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty — Rocket.ChatCWE-347--2026-06-24
CVE-2026-45689 Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO — Rocket.ChatCWE-943 9.1 Critical2026-06-24
CVE-2026-45688 Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAML User Session Hijack — Rocket.ChatCWE-943 9.1 Critical2026-06-24
CVE-2026-45687 Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in sendFileMessage — Rocket.ChatCWE-915 8.5 High2026-06-24
CVE-2026-45677 Rocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoS — Rocket.ChatCWE-862--2026-06-24
CVE-2026-47733 Rocket.Chat: Missing URL protocol sanitization in ImageElement allows javascript: URLs in markdown images — Rocket.ChatCWE-79 4.4 Medium2026-06-24
CVE-2026-30833 Rocket.Chat: NoSQL injection in the EE ddp-streamer-service — Rocket.ChatCWE-943 9.8 -2026-03-06
CVE-2026-30831 Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamer — Rocket.ChatCWE-287 9.8 -2026-03-06
CVE-2026-28514 Rocket.Chat: Users can login with any password via the EE ddp-streamer-service — Rocket.ChatCWE-287 9.8 -2026-03-06
CVE-2026-23477 Rocket.Chat Unauthorized Access to OAuth App Details — Rocket.ChatCWE-269 7.7 High2026-01-14
CVE-2021-32832 ReDOS in Rocket.Chat — Rocket.ChatCWE-400 4.3 Medium2021-08-30

This page lists every published CVE security advisory associated with RocketChat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.