Path Traversal and Data Exposure in Changedetection.io by dgtlmoon
CVE-2026-43891

7.5HIGH

Key Information:

Vendor

Dgtlmoon

Vendor
CVE Published:
12 May 2026

What is CVE-2026-43891?

Changedetection.io, an open-source web page change detection tool, is vulnerable due to its handling of backup file restoration. Before version 0.55.1, an attacker could exploit this flaw by manipulating snapshot paths contained within backup ZIP files. During the backup restoration process, the application incorrectly trusts these attacker-controlled paths and extracts them directly into the live datastore. This results in the unintended retention of malicious files, such as history.txt, which allows the attacker to access sensitive information regarding the targeted local file. This issue has been addressed in version 0.55.1.

Affected Version(s)

changedetection.io < 0.55.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.