Stoat Stoat Backend是Stoat社区的一个后端服务软件。 Stoat Backend 0.7.8之前版本存在输入验证错误漏洞,该漏洞源于未强制实施邀请模式、邮件验证、验证码和盾牌验证等账户创建限制,攻击者可创建无限数量的未经验证邮箱账户,增加拒绝服务风险并破坏服务完整性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63306 | 8.6 HIGH | stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints |
| CVE-2026-63088 | 8.6 HIGH | stoatchat < 0.14.0 SSRF via DNS-based IP Blocklist Bypass |
| CVE-2025-71377 | stoatchat before 20250210-1 Unrestricted Message History Fetch | |
| CVE-2025-71388 | stoatchat 20241213-1 Webhook Token Disclosure via Read Permissions |
No comments yet