Rocket.Chat 8.4.6

8.4.6
Added 1
  • Add per-client rate limiting to the unauthenticated sendForgotPasswordEmail method, matching the REST users.forgotPassword endpoint
Fixed 1
  • Fix special characters not being escaped in the visitor name shown in the Omnichannel queue side panel's message preview
Security 2
  • Security Hotfix
  • Replace http with serverFetch in downloadPublicImportFile to add SSRF protection

From Rocket.Chat

Engine versions
  • Node: 22.22.2
  • Deno: 2.3.1
  • MongoDB: 8.0
  • Apps-Engine: 1.62.0
Patch Changes
View original

Upgraded? How did it go?

Discussion