CVE-2026-65645

EUVD-2026-63805
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters with no schema validation. A MongoDB operator object (e.g. {"$gt": "4"}) can be substituted for a string room-id or message-id. The authorization check resolves to a room the attacker already has access to, while the downstream data query fans out across all rooms - disclosing private thread parents and their full reply content to any low-privilege authenticated user.
The REST route chat.getThreadsList was patched in v5.0 (HackerOne report #1446767) by adding rid: {type:'string'} AJV validation. The equivalent DDP method was never given the same fix and remains exploitable
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 25.55%
Affected Products (NVD)
VendorProductVersion
rocket.chatrocket.chat
𝑥
< 7.10.15
rocket.chatrocket.chat
8.1.0 ≤
𝑥
< 8.1.8
rocket.chatrocket.chat
8.2.0 ≤
𝑥
< 8.2.8
rocket.chatrocket.chat
8.3.0 ≤
𝑥
< 8.3.8
rocket.chatrocket.chat
8.4.0 ≤
𝑥
< 8.4.6
rocket.chatrocket.chat
8.5.0 ≤
𝑥
< 8.5.3
rocket.chatrocket.chat
8.6.0 ≤
𝑥
< 8.6.2
rocket.chatrocket.chat
8.7.0
𝑥
= Vulnerable software versions