MEDIUM4.8Go
GHSA-3v85-fqvh-7rxf· CVE-2026-79663, GO-2026-5100Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
Modified: 8/27/2026
package
pkg:go/github.com/lin-snow/Ech0
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
Modified: 8/27/2026
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
Modified: 8/27/2026
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count
Modified: 8/27/2026
Ech0 comment model's Email field returned on public /api/comments endpoints
Modified: 8/27/2026