Rocket.chat

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 68
    Known Exploited: 0
    11
    Critical Level Threats
    15
    High Level Threats
    42
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-75575

    Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method

    Last Modified: Aug 25, 2026
    Published: Aug 25, 2026

    CVE-2026-65644

    Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue.

    Last Modified: Sep 04, 2026
    Published: Aug 21, 2026

    CVE-2026-65645

    Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters with no schema validation. A MongoDB operator object (e.g. {"$gt": "4"}) can be substituted for a string room-id or message-id. The authorization check resolves to a room the attacker already has access to, while the downstream data query fans out across all rooms - disclosing private thread parents and their full reply content to any low-privilege authenticated user. The REST route chat.getThreadsList was patched in v5.0 (HackerOne report #1446767) by adding rid: {type:'string'} AJV validation. The equivalent DDP method was never given the same fix and remains exploitable

    Last Modified: Sep 04, 2026
    Published: Aug 21, 2026

    CVE-2026-56845

    Unauthenticated local file inclusion via Rocket.Chat /custom-sounds/ directory traversal

    Last Modified: Aug 04, 2026
    Published: Aug 04, 2026

    CVE-2026-58066

    SAML SSO Authentication Bypass via Unbound XML Signature in Rocket.Chat

    Last Modified: Aug 25, 2026
    Published: Jul 30, 2026
    Items Per Page
    Rocket.chat Vulnerabilities & Security CVEs | CVE-DB