{"id":"CVE-2026-25527","aliases":["PYSEC-2026-2124","GHSA-9jj8-v89v-xjvw"],"title":"changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` ro…","summary":"changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=\"..\"`, which causes `send_from_directory(\"static/..\", filename)` to execute. This…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","vendor":"changedetection-io","product":"changedetection-io","ecosystem":"pip","affected":["changedetection-io < 0.53.2"],"patched":["changedetection-io 0.53.2"],"published":"2026-02-19","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/PYSEC-2026-2124","references":[{"url":"https://github.com/dgtlmoon/changedetection.io/commit/9d38b4517364831889b5b0d7b3465fd060403fd4"},{"url":"https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-9jj8-v89v-xjvw"}],"tags":["osv","pip","exploit-available"],"epss":0.0092,"epssPercentile":0.58767,"ingestedAt":"2026-07-13T18:58:07.429Z","exploits":{"nuclei":["CVE-2026-25527"],"checkedAt":"2026-09-23T07:13:56.003Z"},"exploitAvailable":true,"slug":"CVE-2026-25527","body":"## Overview\n\nchangedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=\"..\"`, which causes `send_from_directory(\"static/..\", filename)` to execute. This moves the base directory up to `/app/changedetectionio`, enabling unauthenticated local file read of application source files (e.g., `flask_app.py`). Version 0.53.2 fixes the issue.\n\n## Affected packages\n\n- `changedetection-io < 0.53.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `changedetection-io 0.53.2`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":29.2,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":5037,"id":"CVE-2026-25527","ts":1788887230039,"field":"exploit_available","old":"false","new":"true"},{"seq":3920,"id":"CVE-2026-25527","ts":1788886360732,"field":"exploit_available","old":"true","new":"false"},{"seq":2742,"id":"CVE-2026-25527","ts":1788883027499,"field":"exploit_available","old":"false","new":"true"},{"seq":1771,"id":"CVE-2026-25527","ts":1788882430527,"field":"exploit_available","old":"true","new":"false"},{"seq":877,"id":"CVE-2026-25527","ts":1788881863778,"field":"exploit_available","old":"false","new":"true"}]}