Server-Side Request Forgery Vulnerability in Ech0 by Lin Snow
CVE-2026-79659

8.3HIGH

Key Information:

Vendor

Lin-snow

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79659?

The Ech0 product by Lin Snow, prior to version 4.7.3, has a vulnerability that allows authenticated attackers to exploit a server-side request forgery issue via the fetchPeerConnectInfo function. This flaw arises from the use of unvalidated HTTP requests, enabling attackers to submit arbitrary URLs and potentially access sensitive internal services, including cloud metadata endpoints. By leveraging weaknesses in connection health checks or peer connection operations, malicious users can navigate beyond intended access controls.

Affected Version(s)

Ech0 0 < 4.7.3

Ech0 4.7.3

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.