TOPROCKETCHAT.md

September 12, 2026 · View on GitHub

Top reports from Rocket.Chat program at HackerOne:

  1. Complete authentication bypass to admin permissions to Rocket.Chat - 99 upvotes, $0
  2. Stored XSS in Rocket.Chat HTML File Export — Unauthenticated Entry via LiveChat to Rocket.Chat - 95 upvotes, $0
  3. IDOR vulnerability leads to Deleting message after leaving/getting banned from group using message ID to Rocket.Chat - 85 upvotes, $0
  4. XSS via /api/v1/chat.postMessage to Rocket.Chat - 73 upvotes, $0
  5. Autotranslate DDP Method Exposes Private Messages Without Authentication or Room Access Check to Rocket.Chat - 73 upvotes, $0
  6. account takeover on 3.0.1 version to Rocket.Chat - 65 upvotes, $0
  7. Blind SQL injection in third-party software, that allows to reveal user statistic from rocket.chat and possibly hack into the rocketchat.agilecrm.com to Rocket.Chat - 61 upvotes, $0
  8. Guest Privilege Escalation to admin group to Rocket.Chat - 59 upvotes, $0
  9. Unauthenticated full-read SSRF via Twilio integration to Rocket.Chat - 52 upvotes, $0
  10. Unauthenticated reading of every file via livechat auth and predicting MongoDB ObjectId() to Rocket.Chat - 48 upvotes, $0
  11. Upload of Avatars for other Users to Rocket.Chat - 47 upvotes, $0
  12. Unauthenticated Path Traversal (LFI) via /custom-sounds/ when CustomSounds uses FileSystem storage to Rocket.Chat - 46 upvotes, $0
  13. IDOR: autotranslate.translateMessage Full Message Content Leak to Rocket.Chat - 42 upvotes, $0
  14. Account takeover via XSS to Rocket.Chat - 41 upvotes, $0
  15. Remote Code Execution in Rocket.Chat-Desktop to Rocket.Chat - 40 upvotes, $0
  16. RBAC bypass on App log endpoints via permissionRequired typo — any authenticated user reads admin-only Enterprise App logs to Rocket.Chat - 40 upvotes, $0
  17. Authentication Bypass via XML Signature Wrapping in SAML SSO to Rocket.Chat - 38 upvotes, $0
  18. Remote code execution by hijacking an unclaimed S3 bucket in Rocket.Chat's installation script. to Rocket.Chat - 35 upvotes, $0
  19. Online Status of arbitrary users can be changed to Rocket.Chat - 33 upvotes, $0
  20. Unauthenticated file deletion via deleteFileMessage DDP method allows permanent destruction of any uploaded file to Rocket.Chat - 33 upvotes, $0
  21. Open Redirect in Rocket.Chat to Rocket.Chat - 32 upvotes, $0
  22. XSS leads to RCE on the RocketChat desktop client. to Rocket.Chat - 31 upvotes, $0
  23. Authentication Bypass in login-token Authentication Method to Rocket.Chat - 31 upvotes, $0
  24. NoSQL injection leaks visitor token and livechat messages to Rocket.Chat - 29 upvotes, $0
  25. Registration bypass with leaked Invite Token to Rocket.Chat - 29 upvotes, $0
  26. Unauthenticated SSRF in Voxtelesys integration ('checkUrlForSsrf' Bypass via DNS rebinding) to Rocket.Chat - 28 upvotes, $0
  27. [Security Vulnerability Rocket.chat] HTML Injection into Email via Signup to Rocket.Chat - 27 upvotes, $0
  28. SSRF via improper validation after DNS name resolution in the link-preview feature to Rocket.Chat - 26 upvotes, $0
  29. Bypassing 2FA with conventional session management - open.rocket.chat to Rocket.Chat - 25 upvotes, $0
  30. SSRF via Improper Redirect Validation in Rocket.Chat oEmbed Function to Rocket.Chat - 25 upvotes, $0
  31. Stored XSS in any message (leads to priv esc for all users and file leak + rce via electron app) to Rocket.Chat - 24 upvotes, $0
  32. The initial E2EE password generated by Rocket.Chat mobile can be recovered in a practical timescale. to Rocket.Chat - 23 upvotes, $0
  33. Clickjacking in the admin page to Rocket.Chat - 21 upvotes, $0
  34. Rocket.Chat Server RCE to Rocket.Chat - 21 upvotes, $0
  35. Pre-Auth Blind NoSQL Injection leading to Remote Code Execution to Rocket.Chat - 20 upvotes, $0
  36. Low authorization level at server side API operation e2e.updateGroupKey, let an attacker break the E2E architecture. to Rocket.Chat - 19 upvotes, $0
  37. CSS Injection in Message Avatar to Rocket.Chat - 19 upvotes, $0
  38. Blind XSS in the rocket.chat registration email to Rocket.Chat - 18 upvotes, $0
  39. Unread Messages can leak Message IDs to Rocket.Chat - 17 upvotes, $0
  40. Desktop app RCE (#276031 bypass) to Rocket.Chat - 16 upvotes, $0
  41. XSS in message attachment fileds. to Rocket.Chat - 16 upvotes, $0
  42. Clickjacking at open.rocket.chat to Rocket.Chat - 16 upvotes, $0
  43. DDP methods getThreadsList / getThreadMessages leaks private thread content to any authenticated low privilege user (unpatched sibling of #1446767) to Rocket.Chat - 16 upvotes, $0
  44. SAML authentication bypass to Rocket.Chat - 15 upvotes, $0
  45. Slack Token exposed over internet (Github) to Rocket.Chat - 14 upvotes, $0
  46. Arbitrary file read in Rocket.Chat-Desktop to Rocket.Chat - 14 upvotes, $0
  47. Content-Security Policy bypass with File Uploads to Rocket.Chat - 14 upvotes, $0
  48. Stored HTML Injection (CWE-79) via Livechat Visitor Name to Rocket.Chat - 14 upvotes, $0
  49. API Keys Hardcoded in Github repository to Rocket.Chat - 13 upvotes, $0
  50. Post-Auth Blind NoSQL Injection in the users.list API leads to Remote Code Execution to Rocket.Chat - 13 upvotes, $0
  51. Unauthenticated clients can modify Livechat Business Hours to Rocket.Chat - 13 upvotes, $0
  52. Remote Code Execution in Rocket.Chat Desktop to Rocket.Chat - 12 upvotes, $0
  53. Hi! Security Team Rocket.Chat, It's possible to get information about the users emails without authentication to Rocket.Chat - 12 upvotes, $0
  54. Blind XSS to Rocket.Chat - 12 upvotes, $0
  55. Insecure use of shell.openExternal() in Rocket.Chat Desktop App leading to RCE to Rocket.Chat - 12 upvotes, $0
  56. XSS in various MessageTypes to Rocket.Chat - 12 upvotes, $0
  57. Open redirect open.rocket.chat/file-upload/ID/filename.svg to Rocket.Chat - 11 upvotes, $0
  58. XSS (leads to arbitrary file read in Rocket.Chat-Desktop) to Rocket.Chat - 11 upvotes, $0
  59. Session Hijack via Self-XSS to Rocket.Chat - 11 upvotes, $0
  60. NoSQL injection in listEmojiCustom method call to Rocket.Chat - 11 upvotes, $0
  61. Rocket.Chat Desktop client fails to open browser on 3rd party external actions from PDF documents to Rocket.Chat - 11 upvotes, $0
  62. Improper ACL in Message Starring to Rocket.Chat - 11 upvotes, $0
  63. Moving private messages into vision with updateMessage method to Rocket.Chat - 10 upvotes, $0
  64. Broken access control on apps to Rocket.Chat - 9 upvotes, $0
  65. Possible Domain Takeover on AWS Instance. to Rocket.Chat - 9 upvotes, $0
  66. Regex account takeover to Rocket.Chat - 9 upvotes, $0
  67. TOTP 2 Factor Authentication Bypass to Rocket.Chat - 8 upvotes, $0
  68. Pinning leaks message content to Rocket.Chat - 8 upvotes, $0
  69. XSS (stored) Wizard is saving executable code to Rocket.Chat - 7 upvotes, $0
  70. Reflected Cross-Site Scripting(CVE-2022-32770 ) to Rocket.Chat - 7 upvotes, $0
  71. Impersonation in Sequential Messages to Rocket.Chat - 7 upvotes, $0
  72. Bypass local authentication (PIN code) to Rocket.Chat - 6 upvotes, $0
  73. Improper Access Control - Generic to Rocket.Chat - 6 upvotes, $0
  74. Mute User can disclose private channel members to unauthorized users to Rocket.Chat - 6 upvotes, $0
  75. SAML authentication bypass through unauthenticated addSamlProvider Meteor Call to Rocket.Chat - 5 upvotes, $0
  76. Post-Auth Stored XSS with User Interaction leads to Remote Code Execution to Rocket.Chat - 5 upvotes, $0
  77. Custom crafted message object in Meteor.Call allows remote code execution and impersonation to Rocket.Chat - 5 upvotes, $0
  78. Messages can be hidden regardless of server configuration to Rocket.Chat - 5 upvotes, $0
  79. Cross-Site-Scripting in "Search Messages" to Rocket.Chat - 5 upvotes, $0
  80. User Impersonation through sendMessage options to Rocket.Chat - 5 upvotes, $0
  81. API route chat.getThreadsList leaks private message content to Rocket.Chat - 4 upvotes, $0
  82. Insecure use of shell.openExternal() leads to RCE in Rocket.Chat-Desktop to Rocket.Chat - 4 upvotes, $0
  83. Android App Crashes while sending message to users/ on channel to Rocket.Chat - 3 upvotes, $0
  84. Persistent CSS injection with ’marked’ markdown parser in Rocket.Chat to Rocket.Chat - 3 upvotes, $0
  85. It is possible to elevate privileges for any authenticated user to view permissions matrix and view Direct messages without appropriate permissions. to Rocket.Chat - 3 upvotes, $0
  86. getUserMentionsByChannel leaks messages with mention from private channel to Rocket.Chat - 3 upvotes, $0
  87. REST API gets query as parameter and executes it to Rocket.Chat - 3 upvotes, $0
  88. NoSQL-Injection discloses S3 File Upload URLs to Rocket.Chat - 3 upvotes, $0
  89. Retrospective change of message timestamp and order to Rocket.Chat - 3 upvotes, $0
  90. Maliciously crafted message can cause Rocket.Chat server to stop responding to Rocket.Chat - 3 upvotes, $0
  91. Message ID Enumeration with Action Link Handler to Rocket.Chat - 2 upvotes, $0
  92. getRoomRoles Method leaks Channel Owner to Rocket.Chat - 2 upvotes, $0
  93. Rocket.chat user info security issue to Rocket.Chat - 2 upvotes, $0
  94. getUsersOfRoom discloses users in private channels to Rocket.Chat - 2 upvotes, $0
  95. Unintended information disclosure in the Hubot Log files to Rocket.Chat - 1 upvotes, $0
  96. Message ID Enumeration with Regular Expression in getReadReceipts Meteor method to Rocket.Chat - 1 upvotes, $0