GHSA-3cjx-7cj6-qvq3
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 20, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.