A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the file changedetectionio/flask_app.py of the component Screenshot Handler. Perform…
Low CVSS 3.7
Summary
A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the file changedetectionio/flask_app.py of the component Screenshot Handler. Performing a manipulation of the argument filename results in path traversal. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The exploit has been made public and could be used. The vendor was contacted early abo…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/herantong/cve/blob/main/changedetection.io_path-traversal_CWE-22.md
- https://vuldb.com/cve/CVE-2026-95272
- https://vuldb.com/submit/896579
- https://vuldb.com/vuln/408340
- https://vuldb.com/vuln/408340/cti
Timeline
- nvd_ingest NVD