Impact
An acknowledgment worker in stoatchat processes mass mention messages. By sending five specially crafted role-mention messages authenticated users can terminate all these workers, which stops push notifications and mention badge deployment across the service until the API process is restarted.
Affected Systems
Versions of stoatchat before 0.15.5 are affected. The product is maintained by the stoatchat organization and is distributed under the stoatchat:stoatchat label. All releases older than 0.15.5 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, so the current public exploitation probability is unclear. However, the attack requires an authenticated account and only five crafted messages, which makes the exploitation path relatively straightforward. If an attacker gains access to an authorized account, they can launch the denial of service within minutes, disabling notifications and badges until the application is restarted. Given the moderate severity and straightforward attack vector, the risk to environments using these versions is significant.
OpenCVE Enrichment