Executive brief
Ech0 is a logging and monitoring system used to track server activity and application state. A flaw allows any registered user—not just administrators—to read historical system logs and stream real-time logs via multiple endpoints. An attacker can extract sensitive information such as internal file paths, error traces, database details, and user activity, which can be used to plan more sophisticated attacks on the application.
Technical details
This is a missing authorization vulnerability (CWE-862) in the system log endpoints: GET /api/system/logs, GET /api/system/logs/stream, and WS /ws/system/logs. The vulnerable code in internal/router/dashboard.go registers these endpoints on the AuthRouterGroup without RequireScopes middleware, and the WSRouterGroup applies no authorization middleware at all. While the endpoints require JWT authentication (any logged-in user), they fail to check whether the user has admin privileges before granting access to sensitive logs. An attacker with a non-admin account can read full historical logs and subscribe to real-time streams, exposing internal file paths, error stack traces, module names, and structured log fields. The fix is to add RequireScopes(ScopeAdminSettings) middleware to all three endpoints, as implemented in patched version 4.4.3.
Affected products
- lin-snow Ech0 before 4.4.3
Timeline
- 2026-08-25: disclosed
- 2026-04-09: patched: Patch released as version 4.4.3