Rocket.Chat 8.3.8

8.3.8
Added 1
  • Add per-client rate limiting to the unauthenticated sendForgotPasswordEmail method, matching the REST users.forgotPassword endpoint
Fixed 1
  • Fix special characters not being escaped in the visitor name shown in the Omnichannel queue side panel's message preview
Security 2
  • Security hotfix for vulnerability in Rocket.Chat
  • Replace http with serverFetch in downloadPublicImportFile to add SSRF protection

From Rocket.Chat

Engine versions
  • Node: 22.16.0
  • Deno: 1.43.5
  • MongoDB: 8.0
  • Apps-Engine: 1.61.1
Patch Changes
View original

Upgraded? How did it go?

Discussion