Executive brief
stoatchat, a chat platform based on Revolt, contains a security flaw where users with basic read-only access to a channel can view secret webhook tokens. An attacker can use these tokens to post unauthorized messages, effectively impersonating bots or administrators and bypassing standard channel restrictions. This could lead to misinformation, phishing, or disruption of community operations.
Technical details
An authorization bypass (CWE-639) exists in the webhook fetch endpoint of stoatchat (delta/Revolt). The root cause is an incorrect permission check in `crates/delta/src/routes/channels/webhook_fetch_all.rs`, where the system verified the `ViewChannel` permission instead of the required `ManageWebhooks` permission. A remote attacker with basic authenticated access to a channel can exploit this to retrieve all associated webhooks and their secret tokens. With these tokens, the attacker can send arbitrary messages to the channel via the webhook API, bypassing standard user permission constraints and impersonating legitimate integrations. The issue is fixed in version 20250210-1 (0.8.2).
Affected products
- stoatchat stoatchat (delta/Revolt) 20241213-1 to 20250210-1
Timeline
- 2025-02-10: patched: Fixed in version 20250210-1 (0.8.2)
- 2025-02-10: advisory: GitHub Security Advisory GHSA-8684-rvfj-v3jq published
- 2026-07-16: disclosed: NVD publication date