stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChannel permission instead of requiring ReadMessageHistory. Attackers with ViewChann…
Medium CVSS 6.5
Summary
stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChannel permission instead of requiring ReadMessageHistory. Attackers with ViewChannel access but ReadMessageHistory denied can retrieve individual message content by ID, bypassing the intended history restriction enforced by bulk read routes.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/stoatchat/stoatchat/security/advisories/GHSA-8qp4-h9xf-2vqr
- https://www.vulncheck.com/advisories/stoatchat-before-permission-bypass-via-message-fetch
Timeline
- nvd_ingest NVD