CVE-2026-100676: stoatchat before 0.15.5 Local Filesystem Read via SVG

Published Sep 26, 2026
·
Updated

January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG <image href> values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who causes the service to proxy an attacker-hosted SVG (e.g. via the /proxy endpoint) can determine whether local files exist through observable response-time differences, and can cause supported local image files to be disclosed after re-encoding. Because each referenced file is read in full with no effective limit on the number or total volume of reads, a single request can also generate an unbounded amount of local filesystem I/O and memory pressure (the published proof of concept drives about 4.34 GB of reads), leading to denial of service. The issue is fixed in 0.15.5.

Affected Software

1 affected component
stoatchat January<0.15.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade stoatchat/stoatchat to a version that resolves this vulnerability.

    Fixed in 0.15.5

Event History

Sep 26, 2026
CVE Published
via MITRE·01:23 PM
Data Sourced
via MITRE·01:23 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to unauthenticated exploitation?

Deployments running a version before 0.15.5 are exposed if an unauthenticated remote attacker can cause January to proxy an attacker-hosted resource served with the image/svg+xml content type, such as through the /proxy endpoint.

2

What can an attacker obtain or infer from a successful attack?

An attacker can infer whether local files exist from response-time differences. They can also cause supported local image files to be disclosed after they are re-encoded.

3

Can this be used for denial of service?

Yes. Each referenced local file is read in full, with no effective limit on the number of reads or their total volume, allowing a single request to create unbounded filesystem I/O and memory pressure. The published proof of concept caused about 4.34 GB of reads.

4

What is the available remediation?

Upgrade stoatchat January to version 0.15.5 or later. The issue is fixed in 0.15.5.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203