PT-2026-81283 · Ech0 · Ech0
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ech0 versions prior to 4.7.3
Description
Failure to properly revoke access tokens created with the never-expire option allows attackers to maintain perpetual authenticated access following token theft. This occurs because three revocation mechanisms are flawed: the logout process panics when encountering a nil
ExpiresAt field, the RevokeToken() function skips execution when remainTTL is zero, and the admin delete function fails to blacklist the JTI (JWT ID), leaving stolen tokens cryptographically valid until the JWT secret is rotated.Recommendations
Update to version 4.7.3 or later.
Rotate the JWT secret to invalidate all existing tokens.
Exploit
Fix
Insufficient Session Expiration
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ech0