Impact
This vulnerability occurs in stoatchat versions prior to 0.7.8, where account creation restrictions are not enforced. The system allows attackers to create unlimited accounts without email verification, captcha, or shield verification, even when invite‑only mode is enabled. The result is potential service abuse, increased denial‑of‑service risk, and weakened service integrity. This flaw falls under CWE‑1173, indicating a failure to enforce security policies during account creation.
Affected Systems
The affected product is stoatchat (author stoatchat). All versions before 0.7.8 are vulnerable. No specific sub‑versions are listed, so any deployment running any pre‑0.7.8 release is potentially exposed.
Risk and Exploitability
The CVSS score of 6.9 classifies the issue as moderate severity. The EPSS score is < 1%, indicating a very low exploitation probability. The vulnerability has not been reported in the CISA KEV catalog, indicating no known widespread exploitation. The attack vector is inferred to be via the public account creation endpoint, where users can submit registration requests freely. Successful exploitation would give an attacker the ability to create arbitrary accounts, which can be used to flood the platform or compromise its integrity.
OpenCVE Enrichment