Cross-Site Scripting in changedetection.io by dgtlmoon
CVE-2026-27645
6.1MEDIUM
What is CVE-2026-27645?
changedetection.io is an open-source tool designed for monitoring changes in web pages. Prior to version 0.54.1, it was found to expose a cross-site scripting vulnerability through its RSS single-watch endpoint. This vulnerability arises because the application reflects the UUID path parameter directly in the HTTP response body without proper HTML escaping. As a result, it allows attackers to inject malicious JavaScript code into the response, which can be executed by the user's browser, potentially leading to unauthorized actions or data access. Users are advised to upgrade to version 0.54.1 or later to mitigate this risk.
Affected Version(s)
changedetection.io < 0.54.1
