Skip to content

Rocket.Chat

v8.6.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 16d Communication & Email
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

chat collaboration free javascript meteor mit
+3 more
real-time slack webrtc

Affected surfaces

auth rbac

ReleasePort's take

Moderate signal
editorial:auto 11d

Rocket.Chat 8.6.1 applies a security hotfix (PR #41234) and enforces the `user-generate-access-token` permission for `users.CreateToken`. It also corrects type issues in Apps Engine API, improves room‑permission checks, and updates several core dependencies.

Why it matters: The release fixes two security vulnerabilities—a critical hotfix (severity 90) and a token‑generation permission enforcement (severity 70)—and resolves type mismatches affecting the Apps Engine API; operators should upgrade promptly to mitigate these risks.

Summary

AI summary

Updates Patch Changes, https://github.com/dionisio-bot, and https://docs.rocket.chat/docs/security-fixes-and-updates across a mixed release.

Changes in this release

Security Critical

Security hotfix applied (PR #41234).

Security hotfix applied (PR #41234).

Source: llm_adapter@2026-07-15

Confidence: high

Security High

`users.CreateToken` now enforces `user-generate-access-token` permission.

`users.CreateToken` now enforces `user-generate-access-token` permission.

Source: llm_adapter@2026-07-15

Confidence: high

Dependency Low

Updated dependencies: @rocket.chat/[email protected], @rocket.chat/[email protected], @rocket.chat/[email protected], @rocket.chat/[email protected], @rocket.chat/[email protected].

Updated dependencies: @rocket.chat/[email protected], @rocket.chat/[email protected], @rocket.chat/[email protected], @rocket.chat/[email protected], @rocket.chat/[email protected].

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Corrects FederationLookup type for IUser in apps.

Corrects FederationLookup type for IUser in apps.

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Applies room permission checks consistently during channel‑to‑team conversion or team creation.

Applies room permission checks consistently during channel‑to‑team conversion or team creation.

Source: llm_adapter@2026-07-15

Confidence: high

Full changelog

Engine versions

  • Node: 22.22.3
  • Deno: 2.3.1
  • MongoDB: 8.0
  • Apps-Engine: 1.64.1

Patch Changes

  • Bump @rocket.chat/meteor version.

  • Bump @rocket.chat/meteor version.

  • (#41234 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)

  • (#41243 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)

  • (#41308 by @dionisio-bot) Fixes wrong FederationLookup type assigned to IUser in apps. The correct data is there, but the type does not represent it.

  • (#41292 by @dionisio-bot) Ensures the users.CreateToken endpoint checks for the user-generate-access-token permission when generating a login token for another user

  • (#41276 by @dionisio-bot) Ensures room permission checks are applied consistently regardless of how the room is identified when converting a channel to a team or creating a team from an existing room

  • Updated dependencies [89ab75ca9121feb289a0f5744a526361364b8867, c86d933c267e375b0b32585450cf513b6483c245]:

Security Fixes

  • Security Hotfix (details in https://docs.rocket.chat/docs/security-fixes-and-updates) applied via PRs #41234 and #41243

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Rocket.Chat

Get notified when new releases ship.

Sign up free

About Rocket.Chat

The Secure CommsOS™ for mission-critical operations

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]