PatchSiren

stoatchat CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM stoatchat CVE published 2026-07-18

CVE-2026-57848

The Stoat for Android application contains a vulnerability that allows an attacker to disclose internal files by exploiting the ShareTargetActivity component. This component is exported and can be reached by any process on the device via the android.intent.action.SEND intent. The activity does not validate or filter the incoming URI before using it as an outgoing attachment, allowing an attacker to pass a [truncated]

HIGH stoatchat CVE published 2026-07-16

CVE-2026-63088

A server-side request forgery (SSRF) vulnerability exists in stoatchat before version 0.14.0. This vulnerability allows unauthenticated network-accessible attackers to bypass the DNS-based IP blocklist. The issue arises from incomplete address validation in the url_is_blacklisted function, which only inspects the first resolved address while the underlying HTTP client iterates over all cached addresses.

HIGH stoatchat CVE published 2026-07-16

CVE-2025-71388

CVE-2025-71388 is a high-severity vulnerability in stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1. The issue allows users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens. Using a retrieved token, an attacker can send arbitrary messages to the channel, bypassing channel permissions and impersonating a bot or webhook. The vul [truncated]

HIGH stoatchat CVE published 2026-07-16

CVE-2025-71377

A logic error was found in the query messages route of stoatchat (delta) versions before 20250210-1 (0.8.2). This error allows a remote unauthenticated attacker to craft requests that can download the entire message history of a channel in a single request, potentially leading to denial of service through resource exhaustion. The vulnerability has a CVSS score of 8.7 and is classified as HIGH severity.

MEDIUM stoatchat CVE published 2026-07-16

CVE-2024-58360

CVE-2024-58360 is a vulnerability in stoatchat versions before 0.7.8 that allows for unrestricted account creation. This issue arises from the failure to enforce account creation restrictions, including invite-only mode, email verification, captcha, and shield verification. As a result, attackers can create unlimited accounts with unverified email addresses, increasing the risk of denial-of-service attack [truncated]