megachangelog
Security8.7.1

Rocket.Chat 8.7.1

Patch release with security improvements including per-client rate limiting for password reset requests, SSRF protection in file downloads, and fixes for UI checkbox state and special character handling in Omnichannel messages.

Engine versions

  • Node: 22.22.3
  • Deno: 2.3.1
  • MongoDB: 8.0
  • Apps-Engine: 1.65.1

Patch Changes

  • Bump @rocket.chat/meteor version.

  • Bump @rocket.chat/meteor version.

  • (#41818 by @dionisio-bot) Adds per-client rate limiting to the unauthenticated sendForgotPasswordEmail method, matching the REST users.forgotPassword endpoint

  • (#41820 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)

  • (#41846) Fixes an issue where a MultiSelect option checkbox remained checked after the option was deselected

  • (#41819 by @dionisio-bot) Replace http with serverFetch in downloadPublicImportFile to add SSRF protection

  • (#41817 by @dionisio-bot) Fixes special characters not being escaped in the visitor name shown in the Omnichannel queue side panel's message preview

  • Updated dependencies []:
    • @rocket.chat/core-typings@8.7.1
    • @rocket.chat/rest-typings@8.7.1
securityrate-limitingssrfomnichannelui-fix

Source: original entry ↗