This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+3 more
Affected surfaces
ReleasePort's take
Moderate signalThe release adds permission checks to the users.CreateToken API endpoint and enforces consistent room permission checks during channel‑to‑team conversions or team creation from existing rooms.
Why it matters: Security fact severity is 90; these checks mitigate unauthorized token generation and improper access when converting channels to teams. Addressing them directly reduces risk for developers, SREs, and security engineers managing Rocket.Chat deployments.
Summary
AI summarySecurity Hotfix addressing critical vulnerabilities.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Adds permission check to users.CreateToken endpoint for token generation Adds permission check to users.CreateToken endpoint for token generation Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | Critical |
Adds consistent room permission checks when converting channel to team or creating team from existing room Adds consistent room permission checks when converting channel to team or creating team from existing room Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Updates multiple internal dependencies to newer versions (e.g., @rocket.chat/[email protected], @rocket.chat/[email protected]) Updates multiple internal dependencies to newer versions (e.g., @rocket.chat/[email protected], @rocket.chat/[email protected]) Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
Engine versions
- Node:
22.16.0 - Deno:
1.43.5 - MongoDB:
8.2 - Apps-Engine:
1.59.2
Patch Changes
-
Bump @rocket.chat/meteor version.
-
(#41239 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41248 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41297 by @dionisio-bot) Ensures the
users.CreateTokenendpoint checks for theuser-generate-access-tokenpermission when generating a login token for another user -
(#41289 by @dionisio-bot) Ensures room permission checks are applied consistently regardless of how the room is identified when converting a channel to a team or creating a team from an existing room
-
Updated dependencies [4511f54f5ef67fb76f4d82389da6d6bd4a279c9f]:
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
Security Fixes
- Security Hotfix (details in https://docs.rocket.chat/docs/security-fixes-and-updates)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]