Local File Read Vulnerability in changedetection.io by dgtlmoon
CVE-2026-25527

5.3MEDIUM

Key Information:

Vendor

Dgtlmoon

Vendor
CVE Published:
19 February 2026

What is CVE-2026-25527?

changedetection.io, an open-source web page change detection tool, is susceptible to a local file read vulnerability in versions before 0.53.2. An attacker can exploit this issue via the /static/<group>/<filename> route by providing a crafted parameter that changes the base directory. This allows unauthenticated users to access sensitive application source files, including the main Flask application file, which could lead to further exploitation. The vulnerability has been addressed in version 0.53.2. It is recommended that users update to this version or later to mitigate the risk.

Affected Version(s)

changedetection.io < 0.53.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.