CVE Hunter
SNS

lin-snow/Ech0

Ech0 – An open-source, self-hosted lightweight publishing platform for personal idea sharing.

#go#markdown#memo#self-hosted#social-network#sqlite3#vue#ech0#golang#microblog#notecard#sqlite#vue3
スコア
60
/ 100
Star
1,973
Fork
151
Open Issue
2
サイズ
106MB
言語
Go
最終push
0 日前
Docker

採点内訳

過去CVE 3件 (適量)
直近 push: 0 日前
得意言語 (Go)
オープンissue 2件
大規模 (106MB)
Docker 未対応
1k–10k: 初心者ベスト (★1,973)

※ 各項目の重みは「採点ルール」を参照。合計は 0 で底打ち。

過去の SecurityAdvisory (18 件)

  • Access tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
  • OAuth redirect URI validation ignores path component, enables exchange-code theft
  • Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo
  • MEDIUMGHSA-pj6q-4vq4-r8cg2026/5/3
    PUT /api/echo/like/:id unauthenticated: anonymous callers modify any echo's fav_count
  • MEDIUMGHSA-rgj7-vg8v-j4wr2026/5/3
    Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation
  • MEDIUMGHSA-3v85-fqvh-7rxf2026/5/3
    RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
  • MEDIUMGHSA-rj4g-rqgh-rx9h2026/5/3
    Comment model's Email field returned on public /api/comments endpoints
  • HIGHGHSA-hmmq-qh6g-6wgh2026/4/13
    Authorization bypass on admin endpoints and /ws/system/logs — session tokens skip RequireScopes
  • MEDIUMGHSA-69hx-63pv-f8f42026/4/9
    Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload
  • MEDIUMGHSA-r2x7-427f-rq692026/4/9
    SSRF via DNS Resolution Bypass in Webhook URL Validation
  • MEDIUMGHSA-w8jj-cwmc-wgq22026/4/9
    Missing Authorization on System Logs Allows Non-Admin Information Disclosure
  • MEDIUMGHSA-fwg7-53p4-g33c2026/4/9
    Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
  • MEDIUMGHSA-hm2h-wwwh-g49x2026/4/9
    Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session
  • MEDIUMGHSA-cp79-9mwr-wr492026/4/9
    Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs
  • Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export
  • Unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadata
  • Unauthenticated Server-Side Request Forgery in Website Preview Feature
  • Authenticated user-list exposed data via public `/api/allusers` endpoint