CVE-2026-25527

MEDIUM NUCLEI

changedetection.io <0.53.2 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-25527 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This moves the base directory up to `/app/changedetectionio`, enabling unauthenticated local file read of application source files (e.g., `flask_app.py`). Version 0.53.2 fixes the issue.

Nuclei Templates (1)

changedetection.io <= 0.52.9 - Unauthenticated Path Traversal
MEDIUMVERIFIEDby WRG-11
Shodan: http.html:"changedetection.io"

Scores

CVSS v3 5.3
EPSS 0.0074
EPSS Percentile 49.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
webtechnologies/changedetection < 0.53.2
Published Feb 19, 2026
Tracked Since Feb 19, 2026