stoatchat
6 known vulnerabilities in stoatchat, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-100679 CVSS 7.1 high stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using…
- CVE-2026-100678 CVSS 8.3 high stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to…
- CVE-2026-100677 CVSS 6.9 medium stoatchat before 0.15.5 contains an account enumeration vulnerability in the login endpoint that exposes source file locations in error…
- CVE-2026-100676 CVSS 8.8 high January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG <image href>…
- CVE-2026-100675 CVSS 7.1 high stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes mass mention…
- CVE-2026-100674 CVSS 5.3 medium stoatchat before 0.15.5 fails to revalidate usernames after Unicode sanitization, allowing attackers to create usernames with forbidden…