PT-2026-81289 · Ech0 · Ech0

·

CVE-2026-79670

·

Published

2026-04-10

·

Updated

2026-08-25

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Ech0 versions prior to 4.4.3
Description A stored cross-site scripting issue exists in the file upload endpoint. The application validates the Content-Type using only client-supplied headers without performing server-side inspection. This allows attackers with admin privileges to upload SVG or HTML files containing JavaScript. When these files are accessed by any user, the script executes within the application origin, which can lead to session hijacking and data exfiltration.
Recommendations Update to version 4.4.3 or later.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79670
GHSA-69HX-63PV-F8F4
GO-2026-5172

Affected Products

Ech0