This release includes security fixes for teams reviewing exposed deployments.
✓ No known CVEs patched in this version
Topics
+3 more
Affected surfaces
ReleasePort's take
Moderate signalVersion 8.3.7 introduces a permission check on the users.CreateToken API and enforces consistent room permission logic during channel‑to‑team conversions.
Why it matters: The new token generation permission check (severity 90) prevents unauthorized token creation; enforcing consistent room permissions during conversion safeguards access control for all affected flows.
Summary
AI summarySecurity hotfixes and added permission check for token generation.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Enforces consistent room permission checks during channel-to-team conversion and team creation from existing rooms Enforces consistent room permission checks during channel-to-team conversion and team creation from existing rooms Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | Critical |
Adds permission check to users.CreateToken endpoint for token generation Adds permission check to users.CreateToken endpoint for token generation Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Security | High |
Applies permission check on users.CreateToken for generating login tokens Applies permission check on users.CreateToken for generating login tokens Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Dependency | Low |
Updates @rocket.chat/core-typings, @rocket.chat/model-typings, @rocket.chat/models, and @rocket.chat/rest-typings to latest versions Updates @rocket.chat/core-typings, @rocket.chat/model-typings, @rocket.chat/models, and @rocket.chat/rest-typings to latest versions Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
Engine versions
- Node:
22.16.0 - Deno:
1.43.5 - MongoDB:
8.0 - Apps-Engine:
1.61.1
Patch Changes
-
Bump @rocket.chat/meteor version.
-
(#41237 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41246 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41295 by @dionisio-bot) Ensures the
users.CreateTokenendpoint checks for theuser-generate-access-tokenpermission when generating a login token for another user -
(#41280 by @dionisio-bot) Ensures room permission checks are applied consistently regardless of how the room is identified when converting a channel to a team or creating a team from an existing room
-
Updated dependencies [c15e433d35357f365ec5768d3420cb9c302b4bc4]:
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]