VYPR

stoatchat

by Stoatchat

CVEs (5)

  • CVE-2026-63088Jul 16, 2026
    risk 0.00cvss epss 0.00

    stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypass the DNS-based IP blocklist by exploiting incomplete address validation in the url_is_blacklisted function, which inspects only…

  • CVE-2024-58360Jul 16, 2026
    risk 0.00cvss epss 0.00

    stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with unverified email addresses, increasing denial-of-service risk and…

  • CVE-2026-63306Jul 16, 2026
    risk 0.00cvss epss 0.00

    stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. Attackers can enumerate internal services, fingerprint…

  • CVE-2025-71388Jul 16, 2026
    risk 0.00cvss epss 0.00

    stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, because the webhook fetch endpoint checked for ViewChannel instead of ManageWebhooks.…

  • CVE-2025-71377Jul 16, 2026
    risk 0.00cvss epss 0.00

    stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which the database interprets as 'no limit'. A remote unauthenticated…