This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+3 more
Affected surfaces
ReleasePort's take
Moderate signalRocket.Chat 8.0.8 adds mandatory permission checks to the users.CreateToken API endpoint and enforces consistent room‑permission validation during channel‑to‑team conversions or team creation from existing rooms.
Why it matters: These security patches address high‑severity (severity 90) vulnerabilities affecting token generation and room permission logic; operators should deploy the hotfix immediately to prevent unauthorized token access or misconfigured room permissions.
Summary
AI summarySecurity Hotfix addressing critical vulnerabilities in Rocket.Chat.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Adds permission check to users.CreateToken endpoint for token generation Adds permission check to users.CreateToken endpoint for token generation Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | Critical |
Adds consistent room permission checks during channel‑to‑team conversion or team creation from existing room Adds consistent room permission checks during channel‑to‑team conversion or team creation from existing room Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Updates multiple internal dependencies (e.g., @rocket.chat/core-typings, @rocket.chat/apps, etc.) to newer versions Updates multiple internal dependencies (e.g., @rocket.chat/core-typings, @rocket.chat/apps, etc.) to newer versions Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
Engine versions
- Node:
22.16.0 - Deno:
1.43.5 - MongoDB:
8.2 - Apps-Engine:
1.59.1
Patch Changes
-
Bump @rocket.chat/meteor version.
-
(#41240 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41250 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41298 by @dionisio-bot) Ensures the
users.CreateTokenendpoint checks for theuser-generate-access-tokenpermission when generating a login token for another user -
(#41290 by @dionisio-bot) Ensures room permission checks are applied consistently regardless of how the room is identified when converting a channel to a team or creating a team from an existing room
-
Updated dependencies [1a604e2cc2f20b6ade88d6bf373252fad1f32e3c]:
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
Security Fixes
- Security Hotfix (details not specified in changelog)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]