---
id: CVE-2024-34061
aliases:
  - GHSA-pwgc-w4x9-gw67
  - PYSEC-2026-1243
title: changedetection.io Cross-site Scripting vulnerability
summary: changedetection.io Cross-site Scripting vulnerability
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
vendor: changedetection-io
product: changedetection-io
ecosystem: pip
affected:
  - changedetection-io < 0.45.22
patched:
  - changedetection-io 0.45.22
published: '2024-05-03'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:49:18.754889068Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-pwgc-w4x9-gw67'
references:
  - url: >-
      https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-pwgc-w4x9-gw67
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-34061'
  - url: >-
      https://github.com/dgtlmoon/changedetection.io/commit/c0f000b1d1ce03733460805dbbedde445fe2c762
  - url: 'https://github.com/dgtlmoon/changedetection.io'
  - url: >-
      https://github.com/dgtlmoon/changedetection.io/blob/0.45.21/changedetectionio/forms.py#L226
tags:
  - osv
  - pip
  - exploit-available
epss: 0.01281
epssPercentile: 0.68803
exploits:
  nuclei:
    - CVE-2024-34061
  checkedAt: '2026-09-26T09:05:31.305Z'
exploitAvailable: true
ingestedAt: '2026-07-08T18:25:52.029Z'
---

## Overview

### Summary

Input in parameter notification_urls is not processed resulting in javascript execution in the application

### Details
changedetection.io version: v0.45.21

https://github.com/dgtlmoon/changedetection.io/blob/0.45.21/changedetectionio/forms.py#L226

```
        for server_url in field.data:
            if not apobj.add(server_url):
                message = field.gettext('\'%s\' is not a valid AppRise URL.' % (server_url))
                raise ValidationError(message)
```

### PoC

Setting > ADD Notification URL List

![image](https://github.com/dgtlmoon/changedetection.io/assets/65381453/626eb43b-a414-4b05-92d8-c7345c2a2e75)


```
"><img src=x onerror=alert(document.domain)>
```
![image](https://github.com/dgtlmoon/changedetection.io/assets/65381453/476bd396-2aa2-4642-9c54-fd2c2ef9de79)

Requests

![image](https://github.com/dgtlmoon/changedetection.io/assets/65381453/1f258ef1-149a-4a03-88ab-a2244a69652e)


### Impact
A reflected XSS vulnerability happens when the user input from a URL or POST data is reflected on the page without being stored, thus allowing the attacker to inject malicious content


## Affected packages

- `changedetection-io < 0.45.22`

## Remediation

Upgrade to a patched release:

- `changedetection-io 0.45.22`
