This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+3 more
Affected surfaces
ReleasePort's take
Moderate signalVersion 8.2.7 adds permission checks to the users.CreateToken API and enforces consistent room‑permission logic during channel‑to‑team conversion.
Why it matters: The security hotfix introduces mandatory permission validation for token generation (users.CreateToken) and tightens room‑permission enforcement in conversion/creation flows, directly mitigating privilege‑escalation risks identified in the release.
Summary
AI summarySecurity Hotfixes addressing vulnerabilities in Rocket.Chat.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Adds permission check to users.CreateToken endpoint for token generation Adds permission check to users.CreateToken endpoint for token generation Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | Critical |
Enforces consistent room permission checks during channel‑to‑team conversion and team creation from existing rooms Enforces consistent room permission checks during channel‑to‑team conversion and team creation from existing rooms Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Updates @rocket.chat/core-typings, @rocket.chat/model-typings, @rocket.chat/models, and @rocket.chat/rest-typings to newer versions Updates @rocket.chat/core-typings, @rocket.chat/model-typings, @rocket.chat/models, and @rocket.chat/rest-typings to newer versions Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
Engine versions
- Node:
22.16.0 - Deno:
1.43.5 - MongoDB:
8.0 - Apps-Engine:
1.60.1
Patch Changes
-
Bump @rocket.chat/meteor version.
-
(#41238 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41247 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41296 by @dionisio-bot) Ensures the
users.CreateTokenendpoint checks for theuser-generate-access-tokenpermission when generating a login token for another user -
(#41288 by @dionisio-bot) Ensures room permission checks are applied consistently regardless of how the room is identified when converting a channel to a team or creating a team from an existing room
-
Updated dependencies [20d752e0e4dc1d37518c826dd2be3476a35710b3]:
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
Security Fixes
- Security Hotfix (details in https://docs.rocket.chat/docs/security-fixes-and-updates)
- Security Hotfix (details in https://docs.rocket.chat/docs/security-fixes-and-updates)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]