CVE-2017-1000493: Rocket.chat

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover

Affected products

Published 2018-01-03. Last modified 2026-06-17.