Stoat Stoat Backend是Stoat社区的一个后端服务软件。 Stoat Backend 0.13.5之前版本存在服务端请求伪造漏洞,该漏洞源于/proxy和/embed端点接受任意URL,且未进行DNS解析过滤或私有IP范围验证,可能导致未经身份验证的攻击者利用恶意URL或重定向链枚举内部服务、指纹识别应用并访问实例元数据端点。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-63088 | 8.6 HIGH | stoatchat < 0.14.0 SSRF via DNS-based IP Blocklist Bypass |
| CVE-2024-58360 | 6.5 MEDIUM | stoatchat before 0.7.8 Unrestricted Account Creation |
| CVE-2025-71377 | stoatchat before 20250210-1 Unrestricted Message History Fetch | |
| CVE-2025-71388 | stoatchat 20241213-1 Webhook Token Disclosure via Read Permissions |
No comments yet