---
id: CVE-2026-63306
title: >-
  stoatchat before 0.13.5 contains an unauthenticated server-side request
  forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary
  URLs without DNS resolution filtering or private IP range validation
summary: >-
  stoatchat before 0.13.5 contains an unauthenticated server-side request
  forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary
  URLs without DNS resolution filtering or private IP range validation.
  Attackers can en…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-918
vendor: stoatchat
product: stoatchat
affected:
  - stoatchat < 0.13.5
published: '2026-07-16'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:27.403'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-63306'
references:
  - url: >-
      https://github.com/stoatchat/stoatchat/security/advisories/GHSA-xhww-5g9p-vvq5
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/stoatchat-before-unauthenticated-ssrf-via-proxy-and-embed-endpoints
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/stoatchat/stoatchat/security/advisories/GHSA-xhww-5g9p-vvq5
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-07-16T13:17:07.146090Z'
epss: 0.00409
epssPercentile: 0.33056
ingestedAt: '2026-10-08T16:52:14.701Z'
---

## Overview

stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. Attackers can enumerate internal services, fingerprint applications, and reach instance metadata endpoints by supplying malicious URLs or leveraging redirect chains to access internal infrastructure.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
