Impact
The vulnerability is a missing authorization check in the Subscribe message handler. An authenticated attacker can craft a Subscribe message containing any server identifier and then receive live UserUpdate events for that server. These events reveal display names, avatars, and status changes of members, information that should only be available to users who are members of the private server.
Affected Systems
Versions of stoatchat prior to 0.15.0 are affected. The product is stoatchat, and all releases before the 0.15.0 update contain the flaw.
Risk and Exploitability
The CVSS score of 8.3 reflects a high severity information disclosure vulnerability. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog. Attackers must be authenticated to send a Subscribe request, but once authenticated, they can subscribe to any server’s member‑update topic regardless of membership. The lack of an authorization guard allows wide exposure of private server member data across the user base.
OpenCVE Enrichment