CVE-2026-25527
changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<grou
changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the /static/<group>/<filename> route accepts group="..", which causes send_from_directory("static/..", filename) to execute. This moves the base directory up to /app/changedetectionio, enabling unauthenticated local file read of application source files (e.g., flask_app.py).
Version 0.53.2 fixes the issue.
MEDIUM · CVSS 5.3
EPSS 0.00099
Schedule remediation
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules0
YARA rules0