在 stoatchat 0.15.5 之前的版本中,系统在 Unicode 清洗后未能对用户名进行重新验证,攻击者可以通过提交经过转换的 Unicode 字符来绕过限制,从而创建包含非法字符的用户名。攻击者可以绕过字符白名单和长度限制,创建与保留名称相似的别名、嵌入特殊字符,并超过 32 个字符的存储限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100679 | 8.8 HIGH | stoatchat before 0.15.5 MFA Bypass via Cross-Account Ticket |
| CVE-2026-100676 | 8.2 HIGH | stoatchat before 0.15.5 Local Filesystem Read via SVG |
| CVE-2026-100678 | 6.5 MEDIUM | stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting |
| CVE-2026-100675 | 6.5 MEDIUM | stoatchat before 0.15.5 Denial of Service via mass mentions |
| CVE-2026-100677 | 5.3 MEDIUM | stoatchat before 0.15.5 Account Enumeration via Error Location |
No comments yet