Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 20 Feb 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dgtlmoon
Dgtlmoon changedetection.io |
|
| Vendors & Products |
Dgtlmoon
Dgtlmoon changedetection.io |
Thu, 19 Feb 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webtechnologies
Webtechnologies changedetection |
|
| CPEs | cpe:2.3:a:webtechnologies:changedetection:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webtechnologies
Webtechnologies changedetection |
Thu, 19 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Feb 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This moves the base directory up to `/app/changedetectionio`, enabling unauthenticated local file read of application source files (e.g., `flask_app.py`). Version 0.53.2 fixes the issue. | |
| Title | changedetection.io vulnerable to unauthenticated static path traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-19T15:35:41.155Z
Reserved: 2026-02-02T19:59:47.373Z
Link: CVE-2026-25527
Updated: 2026-02-19T15:35:25.712Z
Status : Analyzed
Published: 2026-02-19T15:16:11.947
Modified: 2026-02-19T19:54:04.670
Link: CVE-2026-25527
No data.
OpenCVE Enrichment
Updated: 2026-02-20T10:06:44Z