A high-severity server-side request forgery flaw tracked as CVE-2026-63306 affects stoatchat versions before 0.13.5, allowing unauthenticated attackers to abuse the /proxy and /embed endpoints with arbitrary URLs. The vulnerable endpoints reportedly lack DNS resolution filtering and private IP range validation, enabling requests to be routed toward internal network resources that should not be externally reachable.
The issue can be used to enumerate internal services, fingerprint internal applications, and access cloud instance metadata endpoints, including by chaining redirects to reach otherwise restricted infrastructure. The vulnerability is classified as CWE-918 and carries a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N; advisory data also indicates proof-of-concept exploitation and automatable attack potential. Version 0.13.5 is listed as unaffected.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2026-63306 was updated on 2026-07-16 with references, affected-version information, CVSS data, and SSVC metadata. The update indicated proof-of-concept exploitation and automatable attack potential, and noted that version 0.13.5 is unaffected.
A disclosure described an unauthenticated SSRF flaw in stoatchat affecting versions before 0.13.5 via the /proxy and /embed endpoints, which accept arbitrary URLs without DNS filtering or private IP validation. The issue can enable internal service enumeration, application fingerprinting, and access to cloud metadata endpoints, including through redirect chains.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.