Description
changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to retrieve responses from restricted network locations.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Server Side Request Forgery (SSRF) that allows attackers to access internal network resources
Action: Patch Now
AI Analysis

Impact

A flaw in changedetection.io allows unauthenticated users to cause the application to request arbitrary URLs through the browser-step "Goto URL" feature. The optional_value parameter is not validated, so the application can retrieve data from internal addresses that should be inaccessible. This flaw can expose confidential internal data, enable lateral movement, or exfiltrate sensitive information. The weakness originates from improper input validation and is identified as CWE‑918.

Affected Systems

The vulnerability is confined to Changedetection.io versions through 0.60.6, distributed by dgtlmoon. Affected installations include all deployments of the product running the 0.60.6 code base, which is no longer current.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, but the EPSS score of <1% shows a very low probability of widespread exploitation at the moment. The flaw is not present in the CISA KEV catalog, so it has not yet been reported as a widely used exploit. Attackers can reach the vulnerable endpoint without authentication, and the SSRF can target any internal or remote address specified in the optional_value field. Because the feature bypasses a guard that only protects the primary watch URL, exploitation requires no additional credentials or privilege escalation beyond the ability to submit a browser step. The risk is primarily for internal network assets that are reachable from the application server.

Generated by OpenCVE AI on September 17, 2026 at 21:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the application to a version newer than 0.60.6 that contains the fixed validation for Goto URL.
  • If an upgrade is not immediately possible, disable the browser-step "Goto URL" functionality in the admin configuration or remove the corresponding browser step from watched pages.
  • Apply network segmentation or firewall rules that prevent the application host from initiating outbound connections to internal IP ranges, thereby limiting the impact of any remaining SSRF vectors.

Generated by OpenCVE AI on September 17, 2026 at 21:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Dgtlmoon
Dgtlmoon changedetection.io
Vendors & Products Dgtlmoon
Dgtlmoon changedetection.io

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to retrieve responses from restricted network locations.
Title changedetection.io through 0.60.6 SSRF via browser-step Goto URL
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Dgtlmoon Changedetection.io
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:56:14.559Z

Reserved: 2026-09-16T19:55:02.854Z

Link: CVE-2026-92815

cve-icon Vulnrichment

Updated: 2026-09-17T14:56:09.930Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:31.503

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-92815

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:15:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)