Stoat Stoat Backend是Stoat社区的一个后端服务软件。 Stoat Backend 0.14.0之前版本存在服务端请求伪造漏洞,该漏洞源于url_is_blacklisted函数中的地址验证不完整,导致未经身份验证的网络攻击者可利用服务端请求伪造漏洞绕过基于DNS的IP黑名单。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63306 | 8.6 HIGH | stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints |
| CVE-2024-58360 | 6.5 MEDIUM | stoatchat before 0.7.8 Unrestricted Account Creation |
| CVE-2025-71377 | stoatchat before 20250210-1 Unrestricted Message History Fetch | |
| CVE-2025-71388 | stoatchat 20241213-1 Webhook Token Disclosure via Read Permissions |
No comments yet