Impact
A flaw in changedetection.io allows unauthenticated users to cause the application to request arbitrary URLs through the browser-step "Goto URL" feature. The optional_value parameter is not validated, so the application can retrieve data from internal addresses that should be inaccessible. This flaw can expose confidential internal data, enable lateral movement, or exfiltrate sensitive information. The weakness originates from improper input validation and is identified as CWE‑918.
Affected Systems
The vulnerability is confined to Changedetection.io versions through 0.60.6, distributed by dgtlmoon. Affected installations include all deployments of the product running the 0.60.6 code base, which is no longer current.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, but the EPSS score of <1% shows a very low probability of widespread exploitation at the moment. The flaw is not present in the CISA KEV catalog, so it has not yet been reported as a widely used exploit. Attackers can reach the vulnerable endpoint without authentication, and the SSRF can target any internal or remote address specified in the optional_value field. Because the feature bypasses a guard that only protects the primary watch URL, exploitation requires no additional credentials or privilege escalation beyond the ability to submit a browser step. The risk is primarily for internal network assets that are reachable from the application server.
OpenCVE Enrichment