{"id":"CVE-2024-58360","summary":"stoatchat before 0.7.8 Unrestricted Account Creation","details":"stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with unverified email addresses, increasing denial-of-service risk and compromising service integrity.","aliases":["GHSA-f26h-rqjq-qqjq"],"modified":"2026-08-12T03:51:41.518890479Z","published":"2026-07-16T12:23:14.567Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58360.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"0.7.8"}]},{"extracted_events":[{"fixed":"0.7.8"}],"source":"DESCRIPTION"}],"cna_assigner":"VulnCheck","cwe_ids":["CWE-1173"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58360.json"},{"type":"ADVISORY","url":"https://github.com/stoatchat/stoatchat/security/advisories/GHSA-f26h-rqjq-qqjq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-58360"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/stoatchat-before-unrestricted-account-creation"},{"type":"FIX","url":"https://github.com/stoatchat/stoatchat/commit/eda36436a862bcab92f7ac2cf1c2dd88c41e52a4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/stoatchat/stoatchat","events":[{"introduced":"0"},{"fixed":"eda36436a862bcab92f7ac2cf1c2dd88c41e52a4"}],"database_specific":{"source":"REFERENCES"}}],"versions":["20240620-2","20240620-1","20240619-1","20240615-1","20240611-3","20240611-2","20240611-1","20240609-1","20240604-1","20240516-1","20240408-4","20240408-3","20240408-2","20240408-1","20240407-1","20240212-1","20240210-2","20240210-1","20240206-1","20231028-2","20231028-1","20231026-01","20230905-1-beta","20230903-2-beta","20230903-1-beta","20230827-3-beta","20230827-2-beta","20230827-1-beta","20230826-1","20230810-3","20230810-2","20230810-1","20230704-1","20230702-1","20230615-1","20230611-5","20230611-4","20230611-3","20230611-2","20230611-1","20230604-1","20230603-3","20230603-2","20230603-1","20221119-1","20221023-2","20221023-1","20220918-2","20220918-1","20220912-1","20220903-1","20220902-1","20220901-1","20220814-1","20220726-1","20220718-1","20220715-1","0.5.5","20220714-1","20220710-1","0.5.4","20220623-1","20220621-1","20220620-1","20220614-1","20220612-4","20220612-3","20220612-2","20220612-1","20220611-1","20220610-2","20220610-1","20220609-1","20220606-1","0.5.3-5-patch.3","0.5.3-5-patch.2","0.5.3-5-patch.1","0.5.3-5","0.5.3-4","0.5.3-3","0.5.3-2","0.5.3-1","0.5.3-patch.2","0.5.3-patch.1","0.5.3","0.5.3-rc.5","0.5.3-rc.4","0.5.3-rc.3","0.5.3-rc.2","0.5.3-rc.1","0.5.3-alpha.16","0.5.3-alpha.15","0.5.3-alpha.14","0.5.3-alpha.13","0.5.3-alpha.11","0.5.3-alpha.10","0.5.3-alpha.9","0.5.3-alpha.8","0.5.3-alpha.7","0.5.3-alpha.6","0.5.0","0.4.1","0.4.0","0.3.3","0.3.3-alpha.7","0.3.3-alpha.6","0.3.3-alpha.5","0.3.3-alpha.4","0.3.3-alpha.3","0.3.3-alpha.2","0.3.3-alpha.1","0.3.3-alpha.0","0.3.2","0.3.1","0.3.0-rc.0","0.3.0","0.2.10","0.2.9","0.2.8","0.2.7","0.2.6","0.2.5","0.2.0","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58360.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"}]}