PT-2026-81279 · Ech0 · Ech0

·

CVE-2026-79660

·

Published

2026-05-07

·

Updated

2026-08-25

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ech0 versions prior to 4.7.3
Description Improper JSON serialization tags on the Comment model allow unauthenticated attackers to harvest guest commenter email addresses. This is achieved by calling the '/api/comments' and '/api/comments/public' API endpoints.
Recommendations Update to version 4.7.3 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79660
GHSA-RJ4G-RQGH-RX9H
GO-2026-5626

Affected Products

Ech0