SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2025-71388

HIGH · CVSS 7.6 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Versions of stoatchat (delta/Revolt) prior to 20250210-1 allow users with only ViewChannel permissions to access sensitive webhook tokens, as the endpoint incorrectly verifies permissions. This vulnerability enables attackers to send arbitrary messages to the channel, effectively bypassing established permissions and impersonating legitimate bots or webhooks. Organizations using affected versions should prioritize this issue to mitigate the risk of unauthorized message injection and potential misinformation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-71388
Severity
HIGH
CVSS
7.6
EPSS
0.27%

Original NVD Description

stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, because the webhook fetch endpoint checked for ViewChannel instead of ManageWebhooks. Using a retrieved token, an attacker can send arbitrary messages to the channel, bypassing channel permissions and impersonating a bot or webhook. Fixed in 20250210-1 (0.8.2).