PT-2026-73146 · Stoatchat · Stoatchat

·

CVE-2026-73059

·

Published

2026-08-16

·

Updated

2026-08-17

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions stoatchat versions prior to 0.15.0
Description A permission bypass exists in the 'message fetch' endpoint. The system only verifies the ViewChannel permission instead of requiring the ReadMessageHistory permission. This allows users who have ViewChannel access but are denied ReadMessageHistory to retrieve individual message content by ID, bypassing the history restrictions applied to bulk read routes.
Recommendations Update to version 0.15.0 or later. As a temporary workaround, restrict access to the 'message fetch' endpoint for users without ReadMessageHistory permissions.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73059
GHSA-8QP4-H9XF-2VQR

Affected Products

Stoatchat