By vendor

Rocket.Chat vulnerabilities

Known CVEs affecting Rocket.Chat products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-48929HIGH 7.5

    Rocket.Chat versions before 8.5.1 (and earlier branches) contain a flaw that allows anyone on the internet to permanently delete files that users have uploaded to the chat platform—without needing to log in. An attacker discovers the ID of a file from public messages or download links, then sends a single command via Rocket.Chat's WebSocket connection that deletes it from the server. The vulnerability stems from a missing authentication check in the file deletion function. Because file IDs are often visible in public channels, this poses a material risk to data integrity and availability for any Rocket.Chat deployment exposed to untrusted networks.