Impact
stoatchat (delta/Revolt) versions prior to 20250210-1 expose webhook tokens to users who only have read access to a channel. Traversing the webhook fetch endpoint, an attacker can obtain the token and use it to send messages that appear as a bot or the channel itself, effectively bypassing channel permissions and impersonating legitimate senders. This flaw permits unauthorized content injection and potential misinformation or spam.
Affected Systems
stoatchat (delta/Revolt) is affected. The vulnerability exists in releases from build 20241213-1 up to, but not including, 20250210-1 (0.8.2).
Risk and Exploitability
The CVSS score of 7.6 indicates a high impact with moderate exploitation complexity. The EPSS score is <1%, indicating a low probability of exploitation, and the issue is not listed in CISA KEV, suggesting no known widespread exploitation yet. Attackers would need legitimate access to the target account with view rights on a channel; from there the flaw allows them to retrieve webhook tokens without elevated ManageWebhooks rights. The vulnerability is exploitable in a web application context where the attacker controls a client session with read permissions.
OpenCVE Enrichment