Email Disclosure in Ech0 Product by Lin-Snow
CVE-2026-79660

6.9MEDIUM

Key Information:

Vendor

Lin-snow

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79660?

Ech0 versions earlier than 4.7.3 have a significant vulnerability where guest commenter email addresses can be revealed through unauthenticated access to public API endpoints. This flaw arises from the improper JSON serialization tags present on the Comment model, allowing malicious users to exploit the /api/comments and /api/comments/public endpoints to harvest email addresses without any authentication.

Affected Version(s)

Ech0 0 < 4.7.3

Ech0 4.7.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

adrgs
aisafe-bot
.