Ech0 4.5.6 及之前版本在 (位于 )中存在 OAuth 重定向 URI 验证漏洞。该函数仅比对学生提供的 的协议(scheme)和主机名(host)与管理员配置的允许列表(allowlist),而忽略了路径(path)、查询字符串(query)和片段标识符(fragment)部分。在登录过程中, 会被嵌入到签名状态 JWT 中,且未经过充分验证。 攻击者可构造一个主机名匹配允许来源、但路径由攻击者控制的 。在完成 OAuth 流程后,受害者将被重定向至该路径,且一次性交换代码(exchange code)
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-79665 | 8.8 HIGH | Ech0 before 4.5.1 Authorization Bypass via Session Tokens |
| CVE-2026-79659 | 7.7 HIGH | Ech0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfo |
| CVE-2026-79667 | 7.6 HIGH | Ech0 before 4.4.3 Authentication Bypass via Scope Enforcement |
| CVE-2026-79658 | 7.5 HIGH | Ech0 before 5.0.1 Denial of Service via Accept-Language |
| CVE-2026-79664 | 7.4 HIGH | Ech0 before 4.7.3 Access Token Revocation Bypass |
| CVE-2026-79673 | 6.5 MEDIUM | Ech0 before 4.4.3 Scope Bypass via profile:read Token |
| CVE-2026-79661 | 6.5 MEDIUM | Ech0 before 4.7.3 Unauthenticated fav_count Modification |
| CVE-2026-79666 | 6.5 MEDIUM | Ech0 before 4.4.3 Missing Authorization via dashboard log endpoints |
| CVE-2026-79672 | 5.5 MEDIUM | Ech0 before 4.4.3 Authentication Bypass via Comment Panel |
| CVE-2026-79671 | 5.5 MEDIUM | Ech0 before 4.4.3 SSRF via DNS Resolution Bypass |
| CVE-2026-79660 | 5.3 MEDIUM | Ech0 before 4.7.3 Email Disclosure via Public API |
| CVE-2026-79668 | 5.3 MEDIUM | Ech0 before 4.7.3 Unauthenticated Like Endpoint Metric Inflation |
| CVE-2026-79670 | 4.8 MEDIUM | Ech0 before 4.4.3 Stored XSS via SVG Upload |
| CVE-2026-79663 | 4.8 MEDIUM | Ech0 before 4.7.3 Stored XSS via RSS feed tag names |
| CVE-2026-79669 | 4.3 MEDIUM | Ech0 before 4.4.3 Missing Authorization on System Logs |
No comments yet