Rocket.Chat vulnerability

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.

Published 3 Aug 2026Updated 9 Sep 20261 sources
CVSS 7.5

What happened

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.

Affected versions

Rocket.Chat: before 8.2.0 (semver); before 8.1.1 (semver); before 8.0.2 (semver); before 7.13.4 (semver); before 7.12.5 (semver); before 7.11.5 (semver); before 7.10.8 (semver) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.