VYPR

Rocket.chat

by RocketChat

npm: rocket.chat

Source repositories

CVEs (80)

  • CVE-2023-28356HigMay 11, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot loop on one of the processes, consuming ~120% CPU and rendering the service unresponsive.

  • CVE-2023-23911HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.00

    An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room.

  • CVE-2021-22892HigMay 27, 2021
    risk 0.49cvss 7.5epss 0.02

    An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks.

  • CVE-2026-45687HigJun 24, 2026
    risk 0.48cvss 8.5epss 0.00

    Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's sendFileMessage DDP method passes the entire attacker-supplied file object into Uploads.updateFileComplete,…

  • CVE-2026-55762HigJun 24, 2026
    risk 0.46cvss 8.1epss 0.00

    Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, the POST /api/v1/fingerprint REST endpoint enforces authentication (authRequired: true) but performs no authorization check. Any…

  • CVE-2024-42027MedOct 7, 2024
    risk 0.44cvss 6.7epss 0.01

    The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they have the appropriate time and resources.

  • CVE-2022-30124MedSep 23, 2022
    risk 0.44cvss 6.8epss 0.01

    An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mobile device to bypass local authentication (PIN code).

  • CVE-2026-48929HigJun 17, 2026
    risk 0.42cvss 7.5epss 0.01

    Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion. The deleteFileMessage Meteor method permanently deletes any uploaded file by ID without requiring authentication. When called via an…

  • CVE-2026-32995HigMay 28, 2026
    risk 0.42cvss 7.5epss 0.00

    The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a client-supplied IMessage object and passes it directly to translateMessage() without checking Meteor.userId() or verifying room…

  • CVE-2024-46935HigSep 25, 2024
    risk 0.42cvss 7.5epss 0.01

    Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.

  • CVE-2023-28325MedMay 11, 2023
    risk 0.42cvss 6.5epss 0.00

    An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target room.

  • CVE-2022-32227MedSep 23, 2022
    risk 0.42cvss 6.5epss 0.01

    A cleartext transmission of sensitive information exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 relating to Oauth tokens by having the permission "view-full-other-user-info", this could cause an oauth token leak in the product.

  • CVE-2022-32220MedSep 23, 2022
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.

  • CVE-2026-55759HigJun 24, 2026
    risk 0.41cvss 7.4epss 0.00

    Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, Rocket.Chat's Apple Sign-In handler verifies JWT signatures but skips claims validation. Any Apple-signed JWT with a non-empty iss…

  • CVE-2023-28358MedMay 11, 2023
    risk 0.40cvss 6.1epss 0.00

    A vulnerability has been discovered in Rocket.Chat where a markdown parsing issue in the "Search Messages" feature allows the insertion of malicious tags. This can be exploited on servers with content security policy disabled possible leading to some issues attacks like account…

  • CVE-2017-1000054MedJul 17, 2017
    risk 0.40cvss 6.1epss 0.01

    Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.

  • CVE-2026-49278MedJun 24, 2026
    risk 0.37cvss 6.7epss 0.00

    Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, in the visitors.info endpoint, https://developer.rocket.chat/apidocs/get-visitor-information-by-id-1, token is returned in…

  • CVE-2024-8270MedJun 11, 2025
    risk 0.36cvss 5.5epss 0.00

    The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Control (TCC) policies, enabling the exploitation or abuse of permissions specified in its entitlements (e.g., microphone, camera, automation, network client).…

  • CVE-2019-17220MedOct 21, 2019
    risk 0.36cvss 6.1epss 0.04

    Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.

  • CVE-2024-45621MedSep 2, 2024
    risk 0.35cvss 5.4epss 0.00

    The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.