Impact
stoatchat before version 0.15.5 does not enforce account‑level limits on MFA login attempts. Attackers who know a user’s password can brute‑force the TOTP code by repeatedly attempting verification, using only IP‑based rate limiting. They can reuse MFA challenge tickets across failed attempts and distribute guesses from multiple IPs, effectively evading the single‑IP restriction. The flaw allows an attacker to gain account access after a successful TOTP guess, leading to potential full account takeover.
Affected Systems
The vulnerable product is stoatchat, supplied by stoatchat. The affected version range is any release prior to 0.15.5. No patch release exists before that date, so users of stoatchat 0.15.4 and earlier are at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.3, indicating high severity. The absence of an EPSS score means current exploitation probability is unknown, but the nature of the flaw—a brute‑force attack that can be distributed across multiple IPs—suggests it could be exploited in realistic scenarios. The vulnerability is not listed in the CISA KEV catalog, but the high severity and potential for abuse warrant immediate attention. Attackers can launch the exploit over the network, using an authenticated password or a user‑known password, to gain the MFA token and then use it to compromise the account.
OpenCVE Enrichment