Medium severity4.8NVD Advisory· Published Aug 25, 2026· Updated Aug 31, 2026
CVE-2026-79663
CVE-2026-79663
Description
Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability in the public RSS feed where tag names and markdown content are rendered without HTML escaping. Attackers with admin privileges can inject malicious tag names or raw HTML in echo content that executes as JavaScript in RSS readers that render HTML-type summaries, affecting anonymous subscribers and other users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
1- Lin Snow Ech0: Fifteen Auth, SSRF, and XSS Flaws Disclosed TogetherVypr Intelligence · Aug 25, 2026