Rocket.Chat AutoTranslate DDP Method Message Exposure Vulnerability

Vulnerability

A vulnerability exists in the Rocket.Chat DDP method 'autoTranslate.translateMessage' in versions prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.5, 7.13.8, and 7.10.12. This vulnerability allows any authenticated DDP user to read private messages from any room, including private channels, direct messages, and end-to-end encrypted rooms. The issue arises because the method accepts a client-supplied IMessage object and passes it directly to 'translateMessage()' without validating the user's identity or room membership.

Impact

Exploitation of this vulnerability allows unauthorized access to private messages from any room, bypassing authentication and room access checks.

Remediation

Users can update to Rocket.Chat versions 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.5, 7.13.8, or 7.10.12 to address this vulnerability.

Added: May 28, 2026, 6:08 AM
Updated: May 28, 2026, 6:08 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
5.4
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.