Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-79669Medium· 4.3Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read and stream all server logs. Attackers can access historical logs and real-time log streams via GET /api/system/logs, G…
CVE-2026-79664High· 7.4Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. Three independent revocation mechanisms fail: logout panics on ni…
CVE-2026-79659High· 7.7Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL validation. Authenticated attackers can supply arbit…
GO-2026-5981NoneEch0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com/lin-snow/ech0
GHSA-mqxv-9rm6-w8qcHighEch0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware
CVE-2026-79660Medium· 5.3Ech0 comment model's Email field returned on public /api/comments endpoints
CVE-2026-79668Medium· 5.3Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation
CVE-2026-79661Medium· 6.5Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count
CVE-2026-79662High· 8.0Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
CVE-2026-79663Medium· 4.8Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
GHSA-fpw6-hrg5-q5x5High· 7.4ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
CVE-2026-79671Medium· 5.5Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation
CVE-2026-79673Medium· 6.5Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session
CVE-2026-79672Medium· 5.5Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
CVE-2026-79666Medium· 6.5Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs
CVE-2026-79670Medium· 4.8Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload
CVE-2026-79667High· 7.6Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.