GHSA-fwg7-53p4-g33c: Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
All 9 comment panel admin endpoints (/api/panel/comments/*) are missing RequireScopes() middleware, while every other admin endpoint in the application enforces scope-based authorization on access tokens. An admin-issued access token scoped to minimal permissions (e.g., echo:read only) can perform full comment moderation operations including listing, approving, rejecting, deleting comments, and modifying comment system settings.
References
Code Behaviors & Features
Detect and mitigate GHSA-fwg7-53p4-g33c with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →