An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.
References
History

Tue, 04 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated local file inclusion via Rocket.Chat /custom-sounds/ directory traversal

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Rocket.chat
Rocket.chat rocket.chat
Vendors & Products Rocket.chat
Rocket.chat rocket.chat

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Description An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.
Weaknesses CWE-22
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2026-08-04T00:43:48.076Z

Updated: 2026-08-04T15:04:12.768Z

Reserved: 2026-06-23T15:00:03.632Z

Link: CVE-2026-56845

cve-icon Vulnrichment

Updated: 2026-08-04T14:28:28.550Z

cve-icon NVD

Status : Received

Published: 2026-08-04T01:16:19.660

Modified: 2026-08-04T16:16:25.600

Link: CVE-2026-56845

cve-icon Redhat

No data.