Rocket.Chat suffers from a path traversal vulnerability.
a823a92ff65ccf73b793d0906e547c53c9b8e1c3527968cc2868bbf6547c16d5
It has been noticed that Rocket.Chat has quietly fixed a persistent cross site scripting vulnerability but as of 12/18/2020 no release contains these fixes.
8c199a1077b7412e93c844e5a21669bc17d54b1e683c9354eb1d77fb10d0d5bc