Email Disclosure in Ech0 Product by Lin-Snow
CVE-2026-79660
6.9MEDIUM
What is CVE-2026-79660?
Ech0 versions earlier than 4.7.3 have a significant vulnerability where guest commenter email addresses can be revealed through unauthenticated access to public API endpoints. This flaw arises from the improper JSON serialization tags present on the Comment model, allowing malicious users to exploit the /api/comments and /api/comments/public endpoints to harvest email addresses without any authentication.
Affected Version(s)
Ech0 0 < 4.7.3
Ech0 4.7.3
