This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+3 more
Affected surfaces
ReleasePort's take
Moderate signalRocket.Chat 8.6.1 applies a security hotfix (PR #41234) and enforces the `user-generate-access-token` permission for `users.CreateToken`. It also corrects type issues in Apps Engine API, improves room‑permission checks, and updates several core dependencies.
Why it matters: The release fixes two security vulnerabilities—a critical hotfix (severity 90) and a token‑generation permission enforcement (severity 70)—and resolves type mismatches affecting the Apps Engine API; operators should upgrade promptly to mitigate these risks.
Summary
AI summaryUpdates Patch Changes, https://github.com/dionisio-bot, and https://docs.rocket.chat/docs/security-fixes-and-updates across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Security hotfix applied (PR #41234). Security hotfix applied (PR #41234). Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | High |
`users.CreateToken` now enforces `user-generate-access-token` permission. `users.CreateToken` now enforces `user-generate-access-token` permission. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Updated dependencies: @rocket.chat/[email protected], @rocket.chat/[email protected], @rocket.chat/[email protected], @rocket.chat/[email protected], @rocket.chat/[email protected]. Updated dependencies: @rocket.chat/[email protected], @rocket.chat/[email protected], @rocket.chat/[email protected], @rocket.chat/[email protected], @rocket.chat/[email protected]. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Corrects FederationLookup type for IUser in apps. Corrects FederationLookup type for IUser in apps. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Applies room permission checks consistently during channel‑to‑team conversion or team creation. Applies room permission checks consistently during channel‑to‑team conversion or team creation. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
Engine versions
- Node:
22.22.3 - Deno:
2.3.1 - MongoDB:
8.0 - Apps-Engine:
1.64.1
Patch Changes
-
Bump @rocket.chat/meteor version.
-
Bump @rocket.chat/meteor version.
-
(#41234 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41243 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41308 by @dionisio-bot) Fixes wrong FederationLookup type assigned to IUser in apps. The correct data is there, but the type does not represent it.
-
(#41292 by @dionisio-bot) Ensures the
users.CreateTokenendpoint checks for theuser-generate-access-tokenpermission when generating a login token for another user -
(#41276 by @dionisio-bot) Ensures room permission checks are applied consistently regardless of how the room is identified when converting a channel to a team or creating a team from an existing room
-
Updated dependencies [89ab75ca9121feb289a0f5744a526361364b8867, c86d933c267e375b0b32585450cf513b6483c245]:
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
Security Fixes
- Security Hotfix (details in https://docs.rocket.chat/docs/security-fixes-and-updates) applied via PRs #41234 and #41243
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]