PT-2026-99348 · Stoatchat · Stoatchat

·

CVE-2026-100677

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions stoatchat versions prior to 0.15.5
Description An account enumeration issue exists in the login endpoint. Unauthenticated attackers can identify whether an email address is registered by analyzing the error location fields returned in the responses of the 'POST /api/auth/session/login' endpoint, which inadvertently expose source file locations.
Recommendations Update stoatchat to version 0.15.5 or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100677
GHSA-H44H-XX2J-HP56

Affected Products

Stoatchat