CVE Explorer
CVE-2026-35037
Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, the GET /api/website/title endpoint accepts an arbitrary URL via the website_url query parameter and makes a server-side HTTP request to it without any validation of the target host or IP address. The endpoint requires no authentication. An attacker can use this to reach internal network services, cloud metadata endpoints (169.254.169.254), and localhost-bound services, with partial response data e
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"Ech0","vendor":"lin-snow","versions":[{"status":"affected","version":"< 4.2.8"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:900421adafbd3bbc317876be397add63109b4248f116fb24176d5819b6c8ed49 · sha256:a747aaf82e851f5a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:900421adafbd3bbc317876be397add63109b4248f116fb24176d5819b6c8ed49 · sha256:a747aaf82e851f5a… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:900421adafbd3bbc317876be397add63109b4248f116fb24176d5819b6c8ed49 · sha256:a747aaf82e851f5a… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/lin-snow/Ech0/security/advisories/GHSA-cqgf-f4x7-g6wc","tags":["x_refsource_CONFIRM"],"url":"https://github.com/lin-snow/Ech0/security/advisories/GHSA-cqgf-f4x7-g6wc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:900421adafbd3bbc317876be397add63109b4248f116fb24176d5819b6c8ed49 · sha256:a747aaf82e851f5a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.