MEDIUM 6.9 NVD
CVE-2026-79660
Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON serialization tags on the Comment model. Una
Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON serialization tags on the Comment model. Unauthenticated attackers can harvest all commenter emails by calling the /api/comments and /api/comments/public endpoints without authentication.
References
- https://github.com/lin-snow/Ech0/security/advisories/GHSA-rj4g-rqgh-rx9h
- https://www.vulncheck.com/advisories/ech0-before-email-disclosure-via-public-api
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-08-25 via NVD.
vulnfeed aggregates 12116 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.