CVE-2024-58360: Stoatchat

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with unverified email addresses, increasing denial-of-service risk and compromising service integrity.

Affected products

  • Stoatchat Stoatchat: before 0.7.8 (fixed in 0.7.8)

Published 2026-07-16. Last modified 2026-07-18.