Security Flaw in Rocket.Chat Communication Platform
CVE-2026-45687
8.5HIGH
What is CVE-2026-45687?
Rocket.Chat, a renowned open-source communication platform, exhibits a vulnerability in its file upload mechanism prior to version 8.5.0. The flaw lies within the sendFileMessage DDP method, where the entirety of the attacker-supplied file object is processed without an allow-list of writable fields. This oversight allows an attacker to manipulate their own upload record, potentially altering database fields such as the store and corresponding paths. Users are advised to upgrade to the fixed versions to mitigate exploitation risks.
Affected Version(s)
Rocket.Chat >= 8.5.0-rc.0, < 8.5.0 < 8.5.0-rc.0, 8.5.0
Rocket.Chat >= 8.4.0-rc.0, < 8.4.1 < 8.4.0-rc.0, 8.4.1
Rocket.Chat >= 8.3.0-rc.0, < 8.3.3 < 8.3.0-rc.0, 8.3.3
