Executive brief
StoatChat, a communication platform, contains a security flaw in its image and link preview components. An unauthorized attacker can use the server to send requests to internal systems that are not normally accessible from the internet. This could allow an attacker to scan private company networks, identify internal databases, or steal sensitive cloud configuration data.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the 'january' service of StoatChat due to insufficient validation of user-supplied URLs in the /proxy and /embed endpoints. The application fails to implement DNS filtering or private IP range rejection (e.g., 10.0.0.0/8, 169.254.169.254), allowing unauthenticated attackers to proxy requests through the server. While a content-type check prevents full data exfiltration of non-media types, attackers can perform blind SSRF to enumerate internal services and ports via error-type differentials. Additionally, the /embed endpoint is susceptible to a second-hop SSRF by recursively fetching URLs found in Open Graph (OG) metadata. The vulnerability is patched in version 0.13.5.
Affected products
- stoatchat stoatchat < 0.13.5
Timeline
- 2026-05-17: disclosed: Advisory published by IAmTomahawkx
- 2026-07-16: advisory: NVD and VulnCheck advisories published