This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+3 more
Affected surfaces
ReleasePort's take
Moderate signalThe release adds permission checks to the users.CreateToken API and enforces consistent room permission logic during channel‑to‑team conversion or team creation from an existing room.
Why it matters: Critical security fixes (severity 90) protect token generation and room access; all deployments using these APIs should upgrade immediately.
Summary
AI summarySecurity hotfixes addressing critical vulnerabilities in Rocket.Chat.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Enforces consistent room permission checks during channel-to-team conversion or team creation from existing room Enforces consistent room permission checks during channel-to-team conversion or team creation from existing room Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | Critical |
Adds permission check to users.CreateToken endpoint for token generation Adds permission check to users.CreateToken endpoint for token generation Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Security | High |
Applies permission check on users.CreateToken for generating login tokens Applies permission check on users.CreateToken for generating login tokens Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Dependency | Low |
Updates @rocket.chat/core-typings to 8.5.2, @rocket.chat/model-typings to 2.3.1, @rocket.chat/models to 2.3.1, @rocket.chat/rest-typings to 8.5.2 Updates @rocket.chat/core-typings to 8.5.2, @rocket.chat/model-typings to 2.3.1, @rocket.chat/models to 2.3.1, @rocket.chat/rest-typings to 8.5.2 Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
Engine versions
- Node:
22.22.3 - Deno:
2.3.1 - MongoDB:
8.0 - Apps-Engine:
1.63.0
Patch Changes
-
Bump @rocket.chat/meteor version.
-
Bump @rocket.chat/meteor version.
-
(#41235 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41244 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41293 by @dionisio-bot) Ensures the
users.CreateTokenendpoint checks for theuser-generate-access-tokenpermission when generating a login token for another user -
(#41277 by @dionisio-bot) Ensures room permission checks are applied consistently regardless of how the room is identified when converting a channel to a team or creating a team from an existing room
-
Updated dependencies [ac29d8a5fa4c032aa0dd9772eddaa060afd3e35e]:
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
Security Fixes
- Security Hotfix (details in https://docs.rocket.chat/docs/security-fixes-and-updates)
- Security Hotfix (details in https://docs.rocket.chat/docs/security-fixes-and-updates)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]