CVE-2022-35249: Rocket.chat

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.

Affected products

Published 2022-09-23. Last modified 2026-06-17.