PT-2026-99347 · Stoatchat · Stoatchat

·

CVE-2026-100676

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions stoatchat versions prior to 0.15.5
Description The media proxy/embed service improperly resolves SVG <image href> values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker can use the /proxy endpoint to proxy a malicious SVG, allowing them to verify the existence of local files via response-time differences and disclose supported local image files through re-encoding. Additionally, since referenced files are read in full without limits on the number or volume of reads, a single request can cause excessive local filesystem I/O and memory pressure, resulting in a denial of service.
Recommendations Update to version 0.15.5.

Exploit

Fix

DoS

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100676
GHSA-QV38-HWHV-JM49

Affected Products

Stoatchat