CVE-2025-71388: stoatchat 20241213-1 Webhook Token Disclosure via Read Permissions

Published Jul 16, 2026
·
Updated

stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, because the webhook fetch endpoint checked for ViewChannel instead of ManageWebhooks. Using a retrieved token, an attacker can send arbitrary messages to the channel, bypassing channel permissions and impersonating a bot or webhook. Fixed in 20250210-1 (0.8.2).

Affected Software

2 affected components
stoatchat stoatchat (delta/Revolt)>20241213-1<20250210-1
stoatchat stoatchat (delta/Revolt)<20250210-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade stoatchat (delta/Revolt) to a version that resolves this vulnerability.

    Fixed in 20250210-1Patch 0.8.2
  2. Compensating control

    Restrict use/access to the webhook fetch endpoint or retrieved-token messaging capability until all instances are upgraded to stoatchat 20250210-1 (0.8.2), since versions from 20241213-1 before 20250210-1 allow ViewChannel (read) users to fetch channel webhooks (including tokens) and allow attackers with a retrieved token to send arbitrary messages while bypassing channel permissions and impersonating a bot or webhook.

Event History

Jul 16, 2026
CVE Published
via MITRE·12:19 PM
Data Sourced
via MITRE·12:19 PM
DescriptionWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-71388?

The severity of CVE-2025-71388 is classified as high with a CVSS score of 7.6.

2

How do I fix CVE-2025-71388?

To fix CVE-2025-71388, upgrade stoatchat to version 20250210-1 or later, which addresses the webhook token disclosure issue.

3

What does CVE-2025-71388 involve?

CVE-2025-71388 involves users being able to fetch webhook tokens due to improper permission checks on the webhook fetch endpoint.

4

Who is affected by CVE-2025-71388?

Users of stoatchat versions from 20241213-1 before 20250210-1 are affected by CVE-2025-71388.

5

Why is CVE-2025-71388 considered a risk?

CVE-2025-71388 is considered a risk because it allows unauthorized access to sensitive webhook tokens that can be exploited.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203