{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/january--0.15.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:stoatchat:stoatchat:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-100676"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["January (\u003c 0.15.5)"],"_cs_severities":["medium"],"_cs_tags":["file-disclosure","denial-of-service","web-application","cve-2026-100676"],"_cs_type":"advisory","_cs_vendors":["stoatchat"],"content_html":"\u003cp\u003eThe January media proxy and embed service within the Stoatchat platform (versions prior to 0.15.5) contains a critical vulnerability regarding how it handles SVG files containing external references. When the service is instructed to proxy an attacker-controlled SVG file via the /proxy endpoint, it fails to sanitize or validate \u0026lt;image href\u0026gt; tags. Instead, it attempts to resolve these paths against the local filesystem.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated remote attacker can exploit this behavior in three ways: by using timing side-channels to determine the existence of local files, by forcing the re-encoding of local image files to disclose their contents, and by generating massive, unbounded filesystem I/O and memory usage. This resource-intensive exploitation can exhaust system memory and disk throughput, leading to a denial-of-service condition. Research indicates a single request can trigger over 4 GB of file reads. This flaw is patched in version 0.15.5.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker hosts a malicious SVG file on an external server containing a crafted \u0026lt;image href\u0026gt; tag targeting a local system path.\u003c/li\u003e\n\u003cli\u003eAttacker sends a GET/POST request to the target's /proxy endpoint, providing the URL of the malicious SVG file.\u003c/li\u003e\n\u003cli\u003eThe January service fetches the SVG file and parses the contents.\u003c/li\u003e\n\u003cli\u003eThe service encounters the \u0026lt;image href\u0026gt; tag and attempts to resolve the provided path on the local filesystem.\u003c/li\u003e\n\u003cli\u003eAttacker observes response times (timing side-channel) to confirm the existence of specific files on the server.\u003c/li\u003e\n\u003cli\u003eService reads the targeted local files into memory, performing re-encoding operations.\u003c/li\u003e\n\u003cli\u003eAttacker requests the proxied output, receiving the disclosed local image content.\u003c/li\u003e\n\u003cli\u003eConcurrent requests lead to excessive I/O and memory pressure, triggering a service crash or system-wide denial-of-service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to the unauthorized disclosure of local image files and denial-of-service. The vulnerability allows an unauthenticated attacker to probe the filesystem structure and extract local image data. Furthermore, the lack of resource constraints allows a single attacker to cause significant system instability through memory exhaustion, potentially impacting all services hosted on the same infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Stoatchat January media proxy service to version 0.15.5 or later immediately.\u003c/li\u003e\n\u003cli\u003eImplement strict egress filtering on the January service host to prevent it from reaching arbitrary external URLs for image proxying if not required by business logic.\u003c/li\u003e\n\u003cli\u003eMonitor webserver logs for excessive requests to the /proxy endpoint, especially those referencing internal or system-like directory paths, to identify exploitation attempts.\u003c/li\u003e\n\u003cli\u003eDeploy network-based rate limiting on the /proxy endpoint to mitigate potential denial-of-service attempts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-26T19:00:23Z","date_published":"2026-09-26T19:00:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-stoatchat-svg-rfi/","summary":"An unauthenticated remote attacker can exploit an improper SVG resolution vulnerability in the Stoatchat January media proxy to perform local file enumeration, arbitrary file disclosure, and memory exhaustion via unbounded filesystem I/O.","title":"Local File Disclosure and Denial of Service in Stoatchat January Service","url":"https://feed.craftedsignal.io/briefs/2026-09-stoatchat-svg-rfi/"}],"language":"en","title":"CraftedSignal Threat Feed - January (\u003c 0.15.5)","version":"https://jsonfeed.org/version/1.1"}