Security Advisories for github.com/lin-snow/ech0 in go
High
23 days ago
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
go
github.com/lin-snow/Ech0
High
23 days ago
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
go
github.com/lin-snow/Ech0
High
23 days ago
Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo
go
github.com/lin-snow/ech0
Moderate
23 days ago
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count
go
github.com/lin-snow/Ech0
Moderate
23 days ago
Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation
go
github.com/lin-snow/ech0
Moderate
23 days ago
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
go
github.com/lin-snow/Ech0
Moderate
23 days ago
Ech0 comment model's Email field returned on public /api/comments endpoints
go
github.com/lin-snow/Ech0
Moderate
about 2 months ago
Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload
go
github.com/lin-snow/ech0
Moderate
about 2 months ago
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation
go
github.com/lin-snow/ech0
Moderate
about 2 months ago
Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure
go
github.com/lin-snow/ech0
Moderate
about 2 months ago
Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
go
github.com/lin-snow/ech0
Moderate
about 2 months ago
Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session
go
github.com/lin-snow/ech0
Moderate
about 2 months ago
Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs
go
github.com/lin-snow/ech0
High
about 2 months ago
Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export
go
github.com/lin-snow/ech0
High
about 2 months ago
Ech0: Unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadata
go
github.com/lin-snow/ech0
High
about 2 months ago
Ech0 has Unauthenticated Server-Side Request Forgery in Website Preview Feature
go
github.com/lin-snow/ech0
Moderate
2 months ago
Ech0 authenticated user-list exposed data via public `/api/allusers` endpoint
go
github.com/lin-snow/ech0