CVE-2026-100677
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
stoatchat before 0.15.5 contains an account enumeration vulnerability in the login endpoint that exposes source file locations in error responses. Unauthenticated attackers can distinguish between registered and unregistered email addresses by comparing error location fields returned from POST /api/auth/session/login requests.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| stoatchat | stoatchat | 0 < 0.15.5 | affected |
| stoatchat | stoatchat | 0.15.5 | unaffected |
Weaknesses
- CWE-209: Generation of Error Message Containing Sensitive Information
References
- https://github.com/stoatchat/stoatchat/security/advisories/GHSA-h44h-xx2j-hp56
- https://www.vulncheck.com/advisories/stoatchat-before-0.15.5-account-enumeration-via-error-location
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.