CyberRota Analysis
AI-GeneratedThe media proxy service in stoatchat versions prior to 0.15.5 is vulnerable to improper handling of SVG <image href> values, allowing unauthenticated remote attackers to exploit this flaw. By proxying attacker-controlled SVG files, they can infer the existence of local files and potentially disclose sensitive data, while also causing significant resource strain that may lead to denial of service. Organizations using affected versions should prioritize upgrading to 0.15.5 to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG <image href> values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who causes the service to proxy an attacker-hosted SVG (e.g. via the /proxy endpoint) can determine whether local files exist through observable response-time differences, and can cause supported local image files to be disclosed after re-encoding. Because each referenced file is read in full with no effective limit on the number or total volume of reads, a single request can also generate an unbounded amount of local filesystem I/O and memory pressure (the published proof of concept drives about 4.34 GB of reads), leading to denial of service. The issue is fixed in 0.15.5.