CVE-2025-71388 - CVE House
Back to Database
Status published High CVE-2025-71388

stoatchat 20241213-1 Webhook Token Disclosure via Read Permissions

Vulnerability Description

stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, because the webhook fetch endpoint checked for ViewChannel instead of ManageWebhooks. Using a retrieved token, an attacker can send arbitrary messages to the channel, bypassing channel permissions and impersonating a bot or webhook. Fixed in 20250210-1 (0.8.2).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71388

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

stoatchat
Vulnerable Versions:
20241213-1, 20250210-1

Timeline

Official Publish: July 16th, 2026
Last Modified: July 16th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)