Local File Read Vulnerability in changedetection.io by dgtlmoon
CVE-2026-25527
5.3MEDIUM
What is CVE-2026-25527?
changedetection.io, an open-source web page change detection tool, is susceptible to a local file read vulnerability in versions before 0.53.2. An attacker can exploit this issue via the /static/<group>/<filename> route by providing a crafted parameter that changes the base directory. This allows unauthenticated users to access sensitive application source files, including the main Flask application file, which could lead to further exploitation. The vulnerability has been addressed in version 0.53.2. It is recommended that users update to this version or later to mitigate the risk.
Affected Version(s)
changedetection.io < 0.53.2
