Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

RocketChat — Vulnerabilities & Security Advisories 20

Browse all 20 CVE security advisories affecting RocketChat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

RocketChat serves as an open-source team communication platform, offering real-time messaging, video conferencing, and file sharing. Historically, it has faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and access control flaws. The platform's self-hosted nature provides organizations with control over their data but requires diligent security maintenance. While no major public security incidents have been widely documented, the presence of five CVEs indicates ongoing security considerations. Users must implement regular updates and hardening measures to mitigate risks, as the platform's extensive feature set and integrations expand its potential attack surface.

Top products by RocketChat: Rocket.Chat
CVE ID Title CVSS Severity Published
CVE-2026-75575 Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method — Rocket.Chat CWE-307 5.3 Medium 2026-08-25
CVE-2026-72919 Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Teams — Rocket.Chat CWE-862 4.3 Medium 2026-08-10
CVE-2026-72918 Rocket.Chat: Insecure implementation of websocket notifications — Rocket.Chat CWE-862 5.4 Medium 2026-08-10
CVE-2026-55762 Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v1/fingerprint` Endpoint — Rocket.Chat CWE-862 8.1 High 2026-06-24
CVE-2026-55759 Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay — Rocket.Chat CWE-287 7.4 High 2026-06-24
CVE-2026-55666 Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth — Rocket.Chat CWE-287 - - 2026-06-24
CVE-2026-49278 Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation — Rocket.Chat CWE-285 6.7 Medium 2026-06-24
CVE-2026-49277 Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation — Rocket.Chat CWE-613 - - 2026-06-24
CVE-2026-45757 Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens — Rocket.Chat CWE-613 - - 2026-06-24
CVE-2026-46423 Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty — Rocket.Chat CWE-347 - - 2026-06-24
CVE-2026-45689 Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO — Rocket.Chat CWE-943 9.1 Critical 2026-06-24
CVE-2026-45688 Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAML User Session Hijack — Rocket.Chat CWE-943 9.1 Critical 2026-06-24
CVE-2026-45687 Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in sendFileMessage — Rocket.Chat CWE-915 8.5 High 2026-06-24
CVE-2026-45677 Rocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoS — Rocket.Chat CWE-862 - - 2026-06-24
CVE-2026-47733 Rocket.Chat: Missing URL protocol sanitization in ImageElement allows javascript: URLs in markdown images — Rocket.Chat CWE-79 4.4 Medium 2026-06-24
CVE-2026-30833 Rocket.Chat: NoSQL injection in the EE ddp-streamer-service — Rocket.Chat CWE-943 9.8 - 2026-03-06
CVE-2026-30831 Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamer — Rocket.Chat CWE-287 9.8 - 2026-03-06
CVE-2026-28514 Rocket.Chat: Users can login with any password via the EE ddp-streamer-service — Rocket.Chat CWE-287 9.8 - 2026-03-06
CVE-2026-23477 Rocket.Chat Unauthorized Access to OAuth App Details — Rocket.Chat CWE-269 7.7 High 2026-01-14
CVE-2021-32832 ReDOS in Rocket.Chat — Rocket.Chat CWE-400 4.3 Medium 2021-08-30

This page lists every published CVE security advisory associated with RocketChat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.