stoatchat
- >= 20241213-1, < 20250210-1
A vulnerability in Stoatchat (Delta/Revolt) versions 20241213-1 prior to 20250210-1 allows users with only ViewChannel (read) permission to access a channel's webhooks and tokens. This issue arises because the webhook fetch endpoint verified ViewChannel instead of ManageWebhooks. An attacker could use the retrieved token to send arbitrary messages to the channel, bypassing permissions and impersonating a bot or webhook.
Exploitation of this vulnerability allows for unauthorized message sending in channels with webhooks, bypassing channel permissions and impersonating a bot or webhook.
Users should upgrade to Stoatchat version 20250210-1 (0.8.2) or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.