Executive brief
Rocket.Chat, a popular communication and collaboration platform, contains a security flaw in how it handles file attachments in its Livechat feature. This vulnerability allows unauthorized individuals to bypass security checks and download private files uploaded by users. Because the file identifiers are predictable, an attacker could systematically discover and steal sensitive documents or data shared within the platform without needing a valid account.
Technical details
An improper access control vulnerability exists in Rocket.Chat's Livechat file handling at the /file-upload/:fileId/:name endpoint. While the system attempts to authorize downloads using room type and token parameters (rc_room_type=l, rc_rid, and rc_token), it fails to verify that the provided room ID (rc_rid) actually matches the room associated with the requested file. Additionally, the :fileId parameter utilizes predictable sequential MongoDB IDs, and the :name parameter is not validated. This combination allows a remote, unauthenticated attacker to iterate through file IDs and download all uploaded files across the instance. The issue is resolved in versions 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, and 7.10.13.
Affected products
- Rocket.Chat Rocket.Chat < 7.10.13, 7.13.0 to < 7.13.9, 8.0.0 to < 8.0.7, 8.1.0 to < 8.1.6, 8.2.0 to < 8.2.6, 8.3.0 to < 8.3.6, 8.4.0 to < 8.4.4, 8.5.0 to < 8.5.1
Timeline
- 2026-06-11: patched: Fix merged into develop branch via PR 40889
- 2026-06-17: disclosed: Initial disclosure via HackerOne/NVD