{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ech0--4.5.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8,"id":"CVE-2026-79662"},{"cvss":7.6,"id":"CVE-2026-79667"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=CVE-2026-79662\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Ech0 (\u003c= 4.5.6)","Ech0 (4.3.4)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Ech0"],"content_html":"\u003cp\u003eEch0 versions up to 4.5.6 contain a critical OAuth redirect URI validation vulnerability located in the parseAndValidateClientRedirect function within internal/service/auth/auth.go. The vulnerability arises because the application only performs allowlist validation on the scheme and host components of a user-supplied redirect_uri, failing to account for path, query, and fragment parameters.\u003c/p\u003e\n\u003cp\u003eThis logic error allows an attacker to craft a redirect_uri that points to a legitimate, allowlisted domain while embedding malicious paths or query strings. When a victim initiates an authentication flow, the application embeds this attacker-controlled URI into the signed state JWT. Following the OAuth exchange, the victim is redirected to the attacker-influenced URI, inadvertently leaking the one-time authorization code. If this code is captured through mechanisms such as Referer headers, analytics logs, or secondary open redirects, the attacker can leverage the /api/auth/exchange endpoint to gain unauthorized access to the victim's account. This flaw is resolved in version 4.7.3.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full account takeover for affected users. By intercepting a valid one-time authorization code, an attacker can exchange it for legitimate access and refresh tokens, effectively bypassing authentication. This risk extends to all users of the affected Ech0 instances, including administrative accounts if they perform authentication in environments where URI leakage is possible.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Ech0 instances to version 4.7.3 or later to patch the redirect validation logic in the authentication service.\u003c/li\u003e\n\u003cli\u003eAudit web server and application logs for suspicious requests to /api/auth/exchange that deviate from normal client-side authentication patterns, such as multiple exchanges originating from anomalous user-agents or unexpected network segments.\u003c/li\u003e\n\u003cli\u003eImplement stricter URI validation policies in all OAuth-enabled services, ensuring that entire URI structures (not just scheme and host) are validated against defined allowlists.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T16:16:49Z","date_published":"2026-08-25T14:08:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ech0-oauth-bypass/","summary":"Ech0 versions 4.5.6 and earlier contain an OAuth redirect URI validation flaw that permits attackers to intercept authorization codes, enabling full account compromise.","title":"OAuth Redirect URI Validation Bypass in Ech0","url":"https://feed.craftedsignal.io/briefs/2026-08-ech0-oauth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Ech0 (\u003c= 4.5.6)","version":"https://jsonfeed.org/version/1.1"}