TOPROCKETCHAT.md
September 12, 2026 · View on GitHub
Top reports from Rocket.Chat program at HackerOne:
- Complete authentication bypass to admin permissions to Rocket.Chat - 99 upvotes, $0
- Stored XSS in Rocket.Chat HTML File Export — Unauthenticated Entry via LiveChat to Rocket.Chat - 95 upvotes, $0
- IDOR vulnerability leads to Deleting message after leaving/getting banned from group using message ID to Rocket.Chat - 85 upvotes, $0
- XSS via /api/v1/chat.postMessage to Rocket.Chat - 73 upvotes, $0
- Autotranslate DDP Method Exposes Private Messages Without Authentication or Room Access Check to Rocket.Chat - 73 upvotes, $0
- account takeover on 3.0.1 version to Rocket.Chat - 65 upvotes, $0
- Blind SQL injection in third-party software, that allows to reveal user statistic from rocket.chat and possibly hack into the rocketchat.agilecrm.com to Rocket.Chat - 61 upvotes, $0
- Guest Privilege Escalation to admin group to Rocket.Chat - 59 upvotes, $0
- Unauthenticated full-read SSRF via Twilio integration to Rocket.Chat - 52 upvotes, $0
- Unauthenticated reading of every file via livechat auth and predicting MongoDB ObjectId() to Rocket.Chat - 48 upvotes, $0
- Upload of Avatars for other Users to Rocket.Chat - 47 upvotes, $0
- Unauthenticated Path Traversal (LFI) via /custom-sounds/ when CustomSounds uses FileSystem storage to Rocket.Chat - 46 upvotes, $0
- IDOR: autotranslate.translateMessage Full Message Content Leak to Rocket.Chat - 42 upvotes, $0
- Account takeover via XSS to Rocket.Chat - 41 upvotes, $0
- Remote Code Execution in Rocket.Chat-Desktop to Rocket.Chat - 40 upvotes, $0
- RBAC bypass on App log endpoints via
permissionRequiredtypo — any authenticated user reads admin-only Enterprise App logs to Rocket.Chat - 40 upvotes, $0 - Authentication Bypass via XML Signature Wrapping in SAML SSO to Rocket.Chat - 38 upvotes, $0
- Remote code execution by hijacking an unclaimed S3 bucket in Rocket.Chat's installation script. to Rocket.Chat - 35 upvotes, $0
- Online Status of arbitrary users can be changed to Rocket.Chat - 33 upvotes, $0
- Unauthenticated file deletion via deleteFileMessage DDP method allows permanent destruction of any uploaded file to Rocket.Chat - 33 upvotes, $0
- Open Redirect in Rocket.Chat to Rocket.Chat - 32 upvotes, $0
- XSS leads to RCE on the RocketChat desktop client. to Rocket.Chat - 31 upvotes, $0
- Authentication Bypass in login-token Authentication Method to Rocket.Chat - 31 upvotes, $0
- NoSQL injection leaks visitor token and livechat messages to Rocket.Chat - 29 upvotes, $0
- Registration bypass with leaked Invite Token to Rocket.Chat - 29 upvotes, $0
- Unauthenticated SSRF in Voxtelesys integration ('checkUrlForSsrf' Bypass via DNS rebinding) to Rocket.Chat - 28 upvotes, $0
- [Security Vulnerability Rocket.chat] HTML Injection into Email via Signup to Rocket.Chat - 27 upvotes, $0
- SSRF via improper validation after DNS name resolution in the link-preview feature to Rocket.Chat - 26 upvotes, $0
- Bypassing 2FA with conventional session management - open.rocket.chat to Rocket.Chat - 25 upvotes, $0
- SSRF via Improper Redirect Validation in Rocket.Chat oEmbed Function to Rocket.Chat - 25 upvotes, $0
- Stored XSS in any message (leads to priv esc for all users and file leak + rce via electron app) to Rocket.Chat - 24 upvotes, $0
- The initial E2EE password generated by Rocket.Chat mobile can be recovered in a practical timescale. to Rocket.Chat - 23 upvotes, $0
- Clickjacking in the admin page to Rocket.Chat - 21 upvotes, $0
- Rocket.Chat Server RCE to Rocket.Chat - 21 upvotes, $0
- Pre-Auth Blind NoSQL Injection leading to Remote Code Execution to Rocket.Chat - 20 upvotes, $0
- Low authorization level at server side API operation e2e.updateGroupKey, let an attacker break the E2E architecture. to Rocket.Chat - 19 upvotes, $0
- CSS Injection in Message Avatar to Rocket.Chat - 19 upvotes, $0
- Blind XSS in the rocket.chat registration email to Rocket.Chat - 18 upvotes, $0
- Unread Messages can leak Message IDs to Rocket.Chat - 17 upvotes, $0
- Desktop app RCE (#276031 bypass) to Rocket.Chat - 16 upvotes, $0
- XSS in message attachment fileds. to Rocket.Chat - 16 upvotes, $0
- Clickjacking at open.rocket.chat to Rocket.Chat - 16 upvotes, $0
- DDP methods getThreadsList / getThreadMessages leaks private thread content to any authenticated low privilege user (unpatched sibling of #1446767) to Rocket.Chat - 16 upvotes, $0
- SAML authentication bypass to Rocket.Chat - 15 upvotes, $0
- Slack Token exposed over internet (Github) to Rocket.Chat - 14 upvotes, $0
- Arbitrary file read in Rocket.Chat-Desktop to Rocket.Chat - 14 upvotes, $0
- Content-Security Policy bypass with File Uploads to Rocket.Chat - 14 upvotes, $0
- Stored HTML Injection (CWE-79) via Livechat Visitor Name to Rocket.Chat - 14 upvotes, $0
- API Keys Hardcoded in Github repository to Rocket.Chat - 13 upvotes, $0
- Post-Auth Blind NoSQL Injection in the users.list API leads to Remote Code Execution to Rocket.Chat - 13 upvotes, $0
- Unauthenticated clients can modify Livechat Business Hours to Rocket.Chat - 13 upvotes, $0
- Remote Code Execution in Rocket.Chat Desktop to Rocket.Chat - 12 upvotes, $0
- Hi! Security Team Rocket.Chat, It's possible to get information about the users emails without authentication to Rocket.Chat - 12 upvotes, $0
- Blind XSS to Rocket.Chat - 12 upvotes, $0
- Insecure use of shell.openExternal() in Rocket.Chat Desktop App leading to RCE to Rocket.Chat - 12 upvotes, $0
- XSS in various MessageTypes to Rocket.Chat - 12 upvotes, $0
- Open redirect open.rocket.chat/file-upload/ID/filename.svg to Rocket.Chat - 11 upvotes, $0
- XSS (leads to arbitrary file read in Rocket.Chat-Desktop) to Rocket.Chat - 11 upvotes, $0
- Session Hijack via Self-XSS to Rocket.Chat - 11 upvotes, $0
- NoSQL injection in listEmojiCustom method call to Rocket.Chat - 11 upvotes, $0
- Rocket.Chat Desktop client fails to open browser on 3rd party external actions from PDF documents to Rocket.Chat - 11 upvotes, $0
- Improper ACL in Message Starring to Rocket.Chat - 11 upvotes, $0
- Moving private messages into vision with updateMessage method to Rocket.Chat - 10 upvotes, $0
- Broken access control on apps to Rocket.Chat - 9 upvotes, $0
- Possible Domain Takeover on AWS Instance. to Rocket.Chat - 9 upvotes, $0
- Regex account takeover to Rocket.Chat - 9 upvotes, $0
- TOTP 2 Factor Authentication Bypass to Rocket.Chat - 8 upvotes, $0
- Pinning leaks message content to Rocket.Chat - 8 upvotes, $0
- XSS (stored) Wizard is saving executable code to Rocket.Chat - 7 upvotes, $0
- Reflected Cross-Site Scripting(CVE-2022-32770 ) to Rocket.Chat - 7 upvotes, $0
- Impersonation in Sequential Messages to Rocket.Chat - 7 upvotes, $0
- Bypass local authentication (PIN code) to Rocket.Chat - 6 upvotes, $0
- Improper Access Control - Generic to Rocket.Chat - 6 upvotes, $0
- Mute User can disclose private channel members to unauthorized users to Rocket.Chat - 6 upvotes, $0
- SAML authentication bypass through unauthenticated
addSamlProviderMeteor Call to Rocket.Chat - 5 upvotes, $0 - Post-Auth Stored XSS with User Interaction leads to Remote Code Execution to Rocket.Chat - 5 upvotes, $0
- Custom crafted message object in Meteor.Call allows remote code execution and impersonation to Rocket.Chat - 5 upvotes, $0
- Messages can be hidden regardless of server configuration to Rocket.Chat - 5 upvotes, $0
- Cross-Site-Scripting in "Search Messages" to Rocket.Chat - 5 upvotes, $0
- User Impersonation through sendMessage options to Rocket.Chat - 5 upvotes, $0
- API route chat.getThreadsList leaks private message content to Rocket.Chat - 4 upvotes, $0
- Insecure use of shell.openExternal() leads to RCE in Rocket.Chat-Desktop to Rocket.Chat - 4 upvotes, $0
- Android App Crashes while sending message to users/ on channel to Rocket.Chat - 3 upvotes, $0
- Persistent CSS injection with ’marked’ markdown parser in Rocket.Chat to Rocket.Chat - 3 upvotes, $0
- It is possible to elevate privileges for any authenticated user to view permissions matrix and view Direct messages without appropriate permissions. to Rocket.Chat - 3 upvotes, $0
- getUserMentionsByChannel leaks messages with mention from private channel to Rocket.Chat - 3 upvotes, $0
- REST API gets
queryas parameter and executes it to Rocket.Chat - 3 upvotes, $0 - NoSQL-Injection discloses S3 File Upload URLs to Rocket.Chat - 3 upvotes, $0
- Retrospective change of message timestamp and order to Rocket.Chat - 3 upvotes, $0
- Maliciously crafted message can cause Rocket.Chat server to stop responding to Rocket.Chat - 3 upvotes, $0
- Message ID Enumeration with Action Link Handler to Rocket.Chat - 2 upvotes, $0
- getRoomRoles Method leaks Channel Owner to Rocket.Chat - 2 upvotes, $0
- Rocket.chat user info security issue to Rocket.Chat - 2 upvotes, $0
- getUsersOfRoom discloses users in private channels to Rocket.Chat - 2 upvotes, $0
- Unintended information disclosure in the Hubot Log files to Rocket.Chat - 1 upvotes, $0
- Message ID Enumeration with Regular Expression in getReadReceipts Meteor method to Rocket.Chat - 1 upvotes, $0