Server-Side Request Forgery Vulnerability in dgtlmoon Changedetection.io Product
CVE-2026-95656
Key Information:
- Vendor
Dgtlmoon
- Status
- Vendor
- CVE Published:
- 22 September 2026
Badges
What is CVE-2026-95656?
A server-side request forgery vulnerability exists in dgtlmoon Changedetection.io affecting the add_watch_ui_snapshot function. This issue arises due to improper handling of the URL argument in the Preview Endpoint, allowing an attacker to manipulate requests sent to the server. Exploitation of this flaw can be executed remotely, potentially exposing sensitive information or enabling further attacks. Upgrading to version 0.60.1 effectively mitigates this risk, as a patch for the vulnerability has been implemented.
Affected Version(s)
changedetection.io 50389b07
changedetection.io 0.60.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
