Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involving an encoded slash.
https://github.com/colemanjp/shinyserver-directory-traversal-source-code-leak
https://blog.rstudio.com/2021/01/13/shiny-server-1-5-16-update/