Security Flaw in Rocket.Chat Communication Platform
CVE-2026-45687

8.5HIGH

Key Information:

Vendor

Rocketchat

Vendor
CVE Published:
24 June 2026

What is CVE-2026-45687?

Rocket.Chat, a renowned open-source communication platform, exhibits a vulnerability in its file upload mechanism prior to version 8.5.0. The flaw lies within the sendFileMessage DDP method, where the entirety of the attacker-supplied file object is processed without an allow-list of writable fields. This oversight allows an attacker to manipulate their own upload record, potentially altering database fields such as the store and corresponding paths. Users are advised to upgrade to the fixed versions to mitigate exploitation risks.

Affected Version(s)

Rocket.Chat >= 8.5.0-rc.0, < 8.5.0 < 8.5.0-rc.0, 8.5.0

Rocket.Chat >= 8.4.0-rc.0, < 8.4.1 < 8.4.0-rc.0, 8.4.1

Rocket.Chat >= 8.3.0-rc.0, < 8.3.3 < 8.3.0-rc.0, 8.3.3

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.