Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100676— stoatchat before 0.15.5 Local Filesystem Read via SVG

Quick assessment

Affected
stoatchat stoatchat
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 stoatchat(stoatchat/stoatchat)的媒体代理/嵌入服务中,0.15.5 版本之前存在一个漏洞:当获取的资源以 image/svg+xml 类型提供服务时,服务会错误地将 SVG 中的 <image href> 值解析为本地文件系统路径。未经身份验证的远程攻击者可以通过让服务代理攻击者-hosted 的 SVG 文件(例如通过 /proxy 端点),利用可观察到的响应时间差异来判断本地文件是否存在,并能够在重新编码后导致受支持的本地图像文件被泄露。由于每个引用的文件都会被完整读取,且对读

CVSS 8.2 · High EPSS 0.40% · P31
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100676

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
stoatchat before 0.15.5 Local Filesystem Read via SVG
Source: CVE Program / CVE List V5
Vulnerability Description
January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG <image href> values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who causes the service to proxy an attacker-hosted SVG (e.g. via the /proxy endpoint) can determine whether local files exist through observable response-time differences, and can cause supported local image files to be disclosed after re-encoding. Because each referenced file is read in full with no effective limit on the number or total volume of reads, a single request can also generate an unbounded amount of local filesystem I/O and memory pressure (the published proof of concept drives about 4.34 GB of reads), leading to denial of service. The issue is fixed in 0.15.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
保护机制失效
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
stoatchat stoatchat 0 ~ 0.15.5 -

II. Public POCs for CVE-2026-100676

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100676

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100676 (1)

Other References for CVE-2026-100676 (1)

Same Patch Batch · stoatchat · 2026-09-26 · 6 CVEs total

CVE-2026-100679 8.8 HIGH stoatchat before 0.15.5 MFA Bypass via Cross-Account Ticket
CVE-2026-100678 6.5 MEDIUM stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting
CVE-2026-100675 6.5 MEDIUM stoatchat before 0.15.5 Denial of Service via mass mentions
CVE-2026-100677 5.3 MEDIUM stoatchat before 0.15.5 Account Enumeration via Error Location
CVE-2026-100674 4.3 MEDIUM stoatchat before 0.15.5 Username Validation Bypass via Unicode Sanitization

IV. Related Vulnerabilities

V. Comments for CVE-2026-100676

No comments yet


Leave a comment