---
id: CVE-2026-95273
title: A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7
summary: >-
  A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7.
  This impacts the function static_content of the file
  changedetectionio/flask_app.py of the component visual_selector_data.
  Executing a manipulation of the argume…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-22
vendor: dgtlmoon
product: changedetection.io
affected:
  - changedetection.io 0.60.0
  - changedetection.io 0.60.1
  - changedetection.io 0.60.2
  - changedetection.io 0.60.3
  - changedetection.io 0.60.4
  - changedetection.io 0.60.5
  - changedetection.io 0.60.6
  - changedetection.io 0.60.7
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:04:55.677'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-95273'
references:
  - url: >-
      https://github.com/herantong/cve/blob/main/changedetection.io_path-traversal-visual-selector_CWE-22
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-95273'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/896580'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408341'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408341/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-22T14:35:05.308788Z'
ingestedAt: '2026-09-22T13:03:40.037Z'
epss: 0.00517
epssPercentile: 0.41463
---

## Overview

A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a manipulation of the argument filename can lead to path traversal. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Distinct from CVE-2026-25527, which fixed a different parameter (group) in the same function. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
