CVE-2025-71388: stoatchat 20241213-1 Webhook Token Disclosure via Read Permissions
stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, because the webhook fetch endpoint checked for ViewChannel instead of ManageWebhooks. Using a retrieved token, an attacker can send arbitrary messages to the channel, bypassing channel permissions and impersonating a bot or webhook. Fixed in 20250210-1 (0.8.2).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
stoatchat (delta/Revolt)to a version that resolves this vulnerability.Fixed in 20250210-1Patch 0.8.2 - Compensating control
Restrict use/access to the webhook fetch endpoint or retrieved-token messaging capability until all instances are upgraded to stoatchat 20250210-1 (0.8.2), since versions from 20241213-1 before 20250210-1 allow ViewChannel (read) users to fetch channel webhooks (including tokens) and allow attackers with a retrieved token to send arbitrary messages while bypassing channel permissions and impersonating a bot or webhook.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71388?
The severity of CVE-2025-71388 is classified as high with a CVSS score of 7.6.
How do I fix CVE-2025-71388?
To fix CVE-2025-71388, upgrade stoatchat to version 20250210-1 or later, which addresses the webhook token disclosure issue.
What does CVE-2025-71388 involve?
CVE-2025-71388 involves users being able to fetch webhook tokens due to improper permission checks on the webhook fetch endpoint.
Who is affected by CVE-2025-71388?
Users of stoatchat versions from 20241213-1 before 20250210-1 are affected by CVE-2025-71388.
Why is CVE-2025-71388 considered a risk?
CVE-2025-71388 is considered a risk because it allows unauthorized access to sensitive webhook tokens that can be exploited.