๐Ÿ” CVE Alert

CVE-2026-65645

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters with no schema validation. A MongoDB operator object (e.g. {"$gt": "4"}) can be substituted for a string room-id or message-id. The authorization check resolves to a room the attacker already has access to, while the downstream data query fans out across all rooms - disclosing private thread parents and their full reply content to any low-privilege authenticated user. The REST route chat.getThreadsList was patched in v5.0 (HackerOne report #1446767) by adding rid: {type:'string'} AJV validation. The equivalent DDP method was never given the same fix and remains exploitable

Vendor rocket.chat
Product rocket.chat
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for rocket.chat rocket.chat

Be the first to know when new unknown vulnerabilities affecting rocket.chat rocket.chat are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Rocket.Chat / Rocket.Chat
0 < 8.8.0 0 < 8.7.1 0 < 8.6.2 0 < 8.5.3 0 < 8.4.6 0 < 8.3.8 0 < 8.2.8 0 < 8.1.8 0 < 7.10.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackerone.com: https://hackerone.com/reports/3852135 github.com: https://github.com/RocketChat/Rocket.Chat/pull/41814

Credits

Aang (iamaangx028)