Critical SSRF Vulnerability Discovered in stoatchat Versions Below 0.13.5
A critical server-side request forgery vulnerability in stoatchat allows unauthenticated attackers to access internal network infrastructure.
A critical security vulnerability, tracked as CVE-2026-63306, has been identified in stoatchat versions prior to 0.13.5. The flaw exists within the /proxy and /embed endpoints, which fail to implement proper DNS resolution filtering or private IP range validation when processing user-supplied URLs.
This server-side request forgery vulnerability allows unauthenticated attackers to supply malicious URLs to the affected endpoints. By leveraging this flaw, unauthorized actors can enumerate internal services, fingerprint applications, and reach sensitive instance metadata endpoints, potentially exposing internal infrastructure.
With a CVSS score of 8.6, this vulnerability is classified as critical. Users are advised to update to version 0.13.5 or later to mitigate the risk of unauthorized access to internal systems.
Sources
- GitHub Security Advisories Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.