stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and /embed endpoints. A…
Medium CVSS 5.8
Summary
stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and /embed endpoints. Attackers can craft requests using IPv6 literal syntax to access services on the loopback interface and retrieve sensitive internal content.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/stoatchat/stoatchat/security/advisories/GHSA-4rmr-77qv-hq47
- https://www.vulncheck.com/advisories/stoatchat-before-ssrf-via-ipv6-unspecified-address-bypass
Timeline
- nvd_ingest NVD