Executive brief
A security vulnerability in Rocket.Chat allows any registered user to steal the private data exports of other users. By exploiting a flaw in how the system handles file uploads, an attacker can trick the server into generating a download link for sensitive ZIP files containing another person's message history and account data. This issue specifically affects organizations using cloud storage like Amazon S3 or Google Cloud Storage and can lead to significant unauthorized data exposure.
Technical details
A mass assignment vulnerability exists in Rocket.Chat's 'sendFileMessage' DDP method. The method passes an attacker-supplied file object to 'Uploads.updateFileComplete', which uses 'Object.assign' to merge the object into a MongoDB '$set' update without an allow-list. An authenticated attacker can overwrite fields in their own upload record, specifically the 'store' and provider-specific 'path' fields (e.g., 'GoogleStorage.path'). Because Rocket.Chat uses deterministic, predictable paths for user data exports (based on the instance's uniqueID and the victim's userId), an attacker can point their own upload record to a victim's export ZIP. When the attacker then requests their own file, the server generates a signed URL for the victim's data, bypassing authorization checks. This affects instances using Amazon S3, Google Cloud Storage, or WebDAV.
Affected products
- RocketChat Rocket.Chat < 8.5.0, < 8.4.1, < 8.3.3, < 8.2.3, < 8.1.4, < 8.0.5, < 7.13.7, < 7.10.11
Timeline
- 2026-05-14: advisory: Vendor advisory published on GitHub
- 2026-06-24: disclosed: CVE published to NVD