Skip to content

Rocket.Chat

v7.10.11 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 21d Communication & Email
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

chat collaboration free javascript meteor mit
+3 more
real-time slack webrtc

Affected surfaces

auth

ReleasePort's take

Light signal
editorial:auto 13d

Version 7.10.11 disables SAML login when signature validation is misconfigured and corrects Slack import errors.

Why it matters: Patch to 7.10.11 immediately if your deployment uses SAML; otherwise treat the Slack fix as a routine upgrade.

Summary

AI summary

Disables SAML login when signature validation is misconfigured and fixes Slack message import errors.

Changes in this release

Security High

Applies a security hotfix (see Rocket.Chat security fixes documentation).

Applies a security hotfix (see Rocket.Chat security fixes documentation).

Source: granite4.1:30b@2026-05-23-audit

Confidence: low

Security Medium

Disables SAML login when signatures are not properly configured.

Disables SAML login when signatures are not properly configured.

Source: llm_adapter@2026-05-21

Confidence: low

Feature Low

Updates Deno runtime to version 1.43.5.

Updates Deno runtime to version 1.43.5.

Source: granite4.1:30b@2026-05-23-audit

Confidence: low

Feature Low

Supports MongoDB versions 5.0, 6.0, and 7.0.

Supports MongoDB versions 5.0, 6.0, and 7.0.

Source: granite4.1:30b@2026-05-23-audit

Confidence: low

Dependency Low

Bumps @rocket.chat/meteor package.

Bumps @rocket.chat/meteor package.

Source: granite4.1:30b@2026-05-23-audit

Confidence: low

Dependency Low

Updates multiple internal dependencies (list provided).

Updates multiple internal dependencies (list provided).

Source: granite4.1:30b@2026-05-23-audit

Confidence: low

Bugfix Medium

Fixes Slack messages being incorrectly saved on import.

Fixes Slack messages being incorrectly saved on import.

Source: llm_adapter@2026-05-21

Confidence: low

Other Low

Updates Node runtime to version 22.16.0.

Updates Node runtime to version 22.16.0.

Source: granite4.1:30b@2026-05-23-audit

Confidence: low

Other Low

Updates Apps-Engine to version 1.55.3.

Updates Apps-Engine to version 1.55.3.

Source: granite4.1:30b@2026-05-23-audit

Confidence: low

Full changelog

Engine versions

  • Node: 22.16.0
  • Deno: 1.43.5
  • MongoDB: 5.0, 6.0, 7.0
  • Apps-Engine: 1.55.3

Patch Changes

Security Fixes

  • Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Rocket.Chat

Get notified when new releases ship.

Sign up free

About Rocket.Chat

The Secure CommsOS™ for mission-critical operations

All releases →

Related context

Beta — feedback welcome: [email protected]