github.com/lin-snow/Ech0
Go4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/lin-snow/Ech0page 1 of 1
- CVE-2026-79660MEDIUMCVSS 5.3EG 5.3✓ Fixed in 1.4.8-0.20260503034700-cb8d7a997dd82026-08-25
Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON serialization tags on the Comment model. Unauthenticated attackers can harvest all commenter emails by calling the /api/com…
- CVE-2026-79661MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.4.8-0.20260503035905-cecc2c19b5902026-08-25
Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on the public router group without authentication or rate limiting. Unauthenticated attackers can increment the fav_count counter of any echo (including private echoes) by su…
- CVE-2026-79662HIGHCVSS 8.0EG 8.0✓ Fixed in 1.4.8-0.20260503040728-a7e8b8e84bd12026-08-25
Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerability in parseAndValidateClientRedirect (internal/service/auth/auth.go) that compares only the scheme and host of the client-supplied redirect_uri against the admin-confi…
- CVE-2026-79663MEDIUMCVSS 4.8EG 4.8✓ Fixed in 1.4.8-0.20260503035519-fd320fe3e9022026-08-25
Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability in the public RSS feed where tag names and markdown content are rendered without HTML escaping. Attackers with admin privileges can inject malicious tag names or raw HT…
Check whether github.com/lin-snow/Ech0 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/lin-snow/Ech0 CVEs against the assets you own.
Start Free Scan →