Rocket.Chat · Rocket.Chat · CVE-2018-13878
**Name of the Vulnerable Software and Affected Versions**
Rocket.Chat versions prior to 0.65
**Description**
A security issue was found in Rocket.Chat where the real name of a username is displayed unescaped when a user is mentioned in a channel or private chat. This allows for the exfiltration of the secret token of every user, including admins, in the channel.
**Recommendations**
For versions prior to 0.65, update to version 0.65 or later to resolve the issue. As a temporary workaround, consider restricting the use of the @ symbol for mentions until the update is applied.