Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6
Published Aug 21, 2026
4.3
MEDIUMCVSS 3.1
EPSS 0.34%
Description
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters with no schema validation. A MongoDB operator object (e.g. {"$gt": "4"}) can be substituted for a string room-id or message-id. The authorization check resolves to a room the attacker already has access to, while the downstream data query fans out across all rooms - disclosing private thread parents and their full reply content to any low-privilege authenticated user. The REST route chat.getThreadsList was patched in v5.0 (HackerOne report #1446767) by adding rid: {type:'string'} AJV validation. The equivalent DDP method was never given the same fix and remains exploitable
Affected products
-
- Version 0StatusaffectedConstraints<7.10.15
- Version 0StatusaffectedConstraints<8.1.8
- Version 0StatusaffectedConstraints<8.2.8
- Version 0StatusaffectedConstraints<8.3.8
- Version 0StatusaffectedConstraints<8.4.6
- Version 0StatusaffectedConstraints<8.5.3
- Version 0StatusaffectedConstraints<8.6.2
- Version 0StatusaffectedConstraints<8.7.1
- Version 0StatusaffectedConstraints<8.8.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Rocket.Chat | Rocket.Chat | unaffected |
|
- < 7.10.15
- ≥ 8.1.0 · < 8.1.8
- ≥ 8.2.0 · < 8.2.8
- ≥ 8.3.0 · < 8.3.8
- ≥ 8.4.0 · < 8.4.6
- ≥ 8.5.0 · < 8.5.3
- ≥ 8.6.0 · < 8.6.2
- 8.7.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 27, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.34% (0.00343) | 25.43th | v5 (v2026.06.15) |
| Aug 21, 2026 | 0.14% (0.00145) | 4.30th | v5 (v2026.06.15) |
References (2)
- https://github.com/RocketChat/Rocket.Chat/pull/41814 PatchVendor Advisory
- https://hackerone.com/reports/3852135 Third Party AdvisoryIssue Tracking
| Link | Providers | Tags |
|---|---|---|
| https://github.com/RocketChat/Rocket.Chat/pull/41814 | PatchVendor Advisory | |
| https://hackerone.com/reports/3852135 | Third Party AdvisoryIssue Tracking |
Change history (0)
No recorded changes yet.