generated: '2026-07-19' method: searched probe: true source: https://www.echo.ai/vulnerability-disclosure policy: - https://www.echo.ai/vulnerability-disclosure contact: - report@echohq.com pgp_fingerprint: 50EDE0CF242CDEBCAE8A001E14E63BE89S2A3E42 cna: true cna_note: Echo is a CVE Numbering Authority (CNA) and assigns CVE identifiers to disclosed vulnerabilities. scope: Security issues found within managed open source code, across affected modules, package managers, and ecosystems. report_requirements: - Affected module - Relevant package manager and ecosystem - Vulnerability details - Steps to reproduce disclosure_timeline: framework: 90-day coordinated disclosure milestones: - {day: 30, event: Maintainer acknowledgment expected} - {day: 45, event: Escalation if no response} - {day: 60, event: Public disclosure may proceed without maintainer collaboration} bug_bounty: none published evidence: - source: https://www.echo.ai/vulnerability-disclosure kind: disclosure page keywords: - responsible disclosure - report@echohq.com - pgp - cve numbering authority