Impact
stoatchat prior to version 0.13.5 exposes an unauthenticated server‑side request forgery flaw in the /proxy and /embed endpoints. These paths accept any supplied URL without validating DNS resolution or filtering private IP ranges, allowing an attacker to send requests to arbitrary internal addresses. The consequence is the potential to enumerate internal services, fingerprint applications, or access sensitive internal endpoints such as instance metadata services, thereby compromising confidentiality and potentially enabling further exploitation. The weakness is identified as CWE‑918.
Affected Systems
The affected product is stoatchat, with vulnerability present in all releases below 0.13.5. No specific patch version range is provided beyond the statement that 0.13.5 and higher contain the fix.
Risk and Exploitability
The CVSS score of 9.2 reflects a high‑severity risk. The EPSS score of <1% indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV. Attackers can exploit the flaw without authentication by sending a malicious HTTP request to the vulnerable endpoints; no additional prerequisites are described, so the attack vector is likely via the public web interface exposed to the Internet.
OpenCVE Enrichment