Rstudio Shiny Server prior to 1.5.16 is vulnerable to local file inclusion and source code leakage. This can be exploited by appending an encoded slash to the URL.
id: CVE-2021-3374
info:
name: Rstudio Shiny Server <1.5.16 - Local File Inclusion
author: geekn
...