These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The CVE-2026-65645 vulnerability affects Rocket.Chat versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15. The Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters without schema validation, allowing a MongoDB operator object to be substituted for a string room-id or message-id. This could lead to disclosure of private thread p [truncated]
Rocket.Chat versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 have a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel, injecting a clickable HTML link into the DOM of any agent viewing the [truncated]
CVE-2026-56845 is a high-severity vulnerability in Rocket.Chat's CustomSounds storage feature, allowing unauthenticated path traversal (LFI) under /custom-sounds/ when configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory. Defenders responsible for Rocket.Chat deployments, particularly those using CustomSounds storage with [truncated]
CVE-2026-48929 is a high-severity vulnerability in Rocket.Chat that allows unauthenticated file deletion. The vulnerability exists in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13. An attacker can exploit this vulnerability by calling the deleteFileMessage Meteor method via an unauthenticated DDP WebSocket connection, which permanently deletes any uploaded file by ID witho [truncated]
A critical vulnerability (CVSS Score: 9.3) was discovered in Rocket.Chat versions prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, and 7.10.13. The vulnerability allows unauthenticated attackers to access Livechat files due to improper authorization in the file download process. Specifically, the authorization path does not verify that the room ID (rc_rid) matches the requested file's room ID, a [truncated]
## Summary Rocket.Chat versions prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.5, 7.13.8, and 7.10.12 contain an insecure direct object reference (IDOR) vulnerability in the DDP method `autoTranslate.translateMessage`. The method accepts a client-supplied `IMessage` object and passes it directly to `translateMessage()` without validating `Meteor.userId()` or verifying room membership. This allows any aut [truncated]
A missing authorization check in the auto-translation API endpoint allows authenticated users to retrieve message content from any room without access verification. The endpoint fetches messages by ID without validating room membership, exposing private communications.