PT-2026-81282 · Ech0 · Ech0

·

CVE-2026-79663

·

Published

2026-05-07

·

Updated

2026-08-25

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Ech0 versions prior to 4.7.3
Description A stored cross-site scripting issue exists in the public RSS feed. The system fails to perform HTML escaping on tag names and markdown content. This allows attackers with admin privileges to inject malicious tag names or raw HTML into echo content, which then executes as JavaScript in RSS readers that render HTML-type summaries, impacting other users and anonymous subscribers.
Recommendations Update to version 4.7.3 or later.

Exploit

Fix

XSS

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79663
GHSA-3V85-FQVH-7RXF
GO-2026-5100

Affected Products

Ech0