CVE-2026-100678: Stoatchat

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across multiple failed attempts and distribute guesses across IP addresses to bypass rate limiting and gain account access.

Affected products

  • Stoatchat Stoatchat: before 0.15.5 (fixed in 0.15.5)

Published 2026-09-26. Last modified 2026-09-30.