CVE-2026-79660
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON serialization tags on the Comment model. Unauthenticated attackers can harvest all commenter emails by calling the /api/comments and /api/comments/public endpoints without authentication.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| lin-snow | Ech0 | 0 < 4.7.3 | affected |
| lin-snow | Ech0 | 4.7.3 | unaffected |
Weaknesses
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: yes
- Technical Impact: partial
Additional References
References
- https://github.com/lin-snow/Ech0/security/advisories/GHSA-rj4g-rqgh-rx9h
- https://www.vulncheck.com/advisories/ech0-before-email-disclosure-via-public-api
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.