Medium severity5.3NVD Advisory· Published Feb 19, 2026· Updated Jun 17, 2026
CVE-2026-25527
CVE-2026-25527
Description
changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the /static// route accepts group="..", which causes send_from_directory("static/..", filename) to execute. This moves the base directory up to /app/changedetectionio, enabling unauthenticated local file read of application source files (e.g., flask_app.py). Version 0.53.2 fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
changedetection.ioPyPI | < 0.53.2 | 0.53.2 |
Affected products
4< 0.53.2+ 1 more
- (no CPE)range: < 0.53.2
- (no CPE)range: <0.53.2
- cpe:2.3:a:webtechnologies:changedetection:*:*:*:*:*:*:*:*Range: <0.53.2
- Range: <0.53.2
Patches
Vulnerability mechanics
References
5- github.com/dgtlmoon/changedetection.io/commit/9d38b4517364831889b5b0d7b3465fd060403fd4nvdPatchWEB
- github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-9jj8-v89v-xjvwnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-9jj8-v89v-xjvwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-25527ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/changedetection-io/PYSEC-2026-2124.yamlghsaWEB
News mentions
0No linked articles in our index yet.