Path Traversal and Data Exposure in Changedetection.io by dgtlmoon
CVE-2026-43891
7.5HIGH
What is CVE-2026-43891?
Changedetection.io, an open-source web page change detection tool, is vulnerable due to its handling of backup file restoration. Before version 0.55.1, an attacker could exploit this flaw by manipulating snapshot paths contained within backup ZIP files. During the backup restoration process, the application incorrectly trusts these attacker-controlled paths and extracts them directly into the live datastore. This results in the unintended retention of malicious files, such as history.txt, which allows the attacker to access sensitive information regarding the targeted local file. This issue has been addressed in version 0.55.1.
Affected Version(s)
changedetection.io < 0.55.1
