在 stoatchat 0.15.5 版本之前,存在一个漏洞,未验证多因素认证(MFA)票证是否属于已认证用户。攻击者可以通过使用自己的有效票证配合其他用户的会话令牌,绕过 MFA 验证。攻击者可以从自己的账户中获取一个票证,并将其与受害者的会话令牌结合使用,从而无需提供受害者的凭证即可禁用 TOTP、查看恢复代码或执行其他敏感操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100676 | 8.2 HIGH | stoatchat before 0.15.5 Local Filesystem Read via SVG |
| CVE-2026-100678 | 6.5 MEDIUM | stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting |
| CVE-2026-100675 | 6.5 MEDIUM | stoatchat before 0.15.5 Denial of Service via mass mentions |
| CVE-2026-100677 | 5.3 MEDIUM | stoatchat before 0.15.5 Account Enumeration via Error Location |
| CVE-2026-100674 | 4.3 MEDIUM | stoatchat before 0.15.5 Username Validation Bypass via Unicode Sanitization |
No comments yet