在 stoatchat(stoatchat/stoatchat)的媒体代理/嵌入服务中,0.15.5 版本之前存在一个漏洞:当获取的资源以 image/svg+xml 类型提供服务时,服务会错误地将 SVG 中的 <image href> 值解析为本地文件系统路径。未经身份验证的远程攻击者可以通过让服务代理攻击者-hosted 的 SVG 文件(例如通过 /proxy 端点),利用可观察到的响应时间差异来判断本地文件是否存在,并能够在重新编码后导致受支持的本地图像文件被泄露。由于每个引用的文件都会被完整读取,且对读
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100679 | 8.8 HIGH | stoatchat before 0.15.5 MFA Bypass via Cross-Account Ticket |
| CVE-2026-100678 | 6.5 MEDIUM | stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting |
| CVE-2026-100675 | 6.5 MEDIUM | stoatchat before 0.15.5 Denial of Service via mass mentions |
| CVE-2026-100677 | 5.3 MEDIUM | stoatchat before 0.15.5 Account Enumeration via Error Location |
| CVE-2026-100674 | 4.3 MEDIUM | stoatchat before 0.15.5 Username Validation Bypass via Unicode Sanitization |
No comments yet