Stoat Stoat Backend是Stoat社区的一个后端服务软件。 Stoat Backend 20241213-1版本至20250210-1之前版本存在授权问题漏洞,该漏洞源于webhook fetch端点检查了ViewChannel权限而非ManageWebhooks权限,允许仅具有ViewChannel(读取)权限的用户获取频道的webhooks及其令牌,攻击者可使用检索到的令牌绕过频道权限并冒充机器人或webhook,向频道发送任意消息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63306 | 8.6 HIGH | stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints |
| CVE-2026-63088 | 8.6 HIGH | stoatchat < 0.14.0 SSRF via DNS-based IP Blocklist Bypass |
| CVE-2024-58360 | 6.5 MEDIUM | stoatchat before 0.7.8 Unrestricted Account Creation |
| CVE-2025-71377 | stoatchat before 20250210-1 Unrestricted Message History Fetch |
No comments yet