Stoatchat · Stoatchat · CVE-2026-100676
**Name of the Vulnerable Software and Affected Versions**
stoatchat versions prior to 0.15.5
**Description**
The media proxy/embed service improperly resolves SVG `<image href>` values as local filesystem paths when a fetched resource is served as `image/svg+xml`. An unauthenticated remote attacker can use the `/proxy` endpoint to proxy a malicious SVG, allowing them to verify the existence of local files via response-time differences and disclose supported local image files through re-encoding. Additionally, since referenced files are read in full without limits on the number or volume of reads, a single request can cause excessive local filesystem I/O and memory pressure, resulting in a denial of service.
**Recommendations**
Update to version 0.15.5.