PT-2026-99347 · Stoatchat · Stoatchat
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
stoatchat versions prior to 0.15.5
Description
The media proxy/embed service improperly resolves SVG
<image href> values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker can use the /proxy endpoint to proxy a malicious SVG, allowing them to verify the existence of local files via response-time differences and disclose supported local image files through re-encoding. Additionally, since referenced files are read in full without limits on the number or volume of reads, a single request can cause excessive local filesystem I/O and memory pressure, resulting in a denial of service.Recommendations
Update to version 0.15.5.
Exploit
Fix
DoS
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stoatchat