Executive brief
Rocket.Chat is an open-source communications platform used for team collaboration and messaging. A security flaw in its login system allows an unauthenticated attacker to hijack the sessions of other users, including administrators, when they log in using Single Sign-On (SSO) services like CAS or SAML. If an administrator's account is compromised, the attacker could gain full control over the server, potentially leading to data theft or complete service disruption.
Technical details
A NoSQL injection vulnerability exists in the CAS login handler of Rocket.Chat due to a lack of type validation on the 'options.cas.credentialToken' parameter. While TypeScript annotations suggest a string, the runtime erasure allows an attacker to pass a MongoDB query operator (e.g., {"$gt": ""}) into a 'findOne' query. This bypasses the intended ticket check by matching any unexpired document in the 'credential_tokens' collection. Because the CAS handler is registered unconditionally and shares a collection with the SAML provider, attackers can intercept session tokens for any user performing an SSO login within a 60-second window. Successful exploitation provides a full Meteor authentication token, which can be used to access REST and DDP APIs. If an administrator is targeted, the attacker can achieve RCE via the Apps-Engine. The issue is fixed in versions 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11.
Affected products
- RocketChat Rocket.Chat < 8.5.0, < 8.4.1, < 8.3.3, < 8.2.3, < 8.1.4, < 8.0.5, < 7.13.7, < 7.10.11
Timeline
- 2026-05-14: advisory: Vendor security advisory published on GitHub
- 2026-06-24: disclosed: CVE published to NVD