<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:00:22.592600+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-217405</id>
    <title>EUVD-2026-217405</title>
    <updated>2026-10-03T20:00:22.687575+00:00</updated>
    <content>EUVD-2026-217405</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-217405"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-32651</id>
    <title>fkie_cve-2024-32651</title>
    <updated>2026-10-03T20:00:22.687612+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn't required by the application (not by default and not enforced).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-32651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4r7v-whpg-8rx3</id>
    <title>GHSA-4r7v-whpg-8rx3 — changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution</title>
    <updated>2026-10-03T20:00:22.687649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: changedetection.io</p>
<p>### Summary
A Server Side Template Injection in changedetection.io caused by usage of unsafe functions of Jinja2 allows Remote Command Execution on the server host.</p>
<p>### Details</p>
<p>changedetection.io version: 0.45.20
```
docker images
REPOSITORY                            TAG       IMAGE ID       CREATED        SIZE
dgtlmoon/changedetection.io           latest    53529c2e69f1   44 hours ago   423MB
```</p>
<p>The vulnerability is caused by the usage of vulnerable functions of Jinja2 template engine.
```python
from jinja2 import Environment, BaseLoader
...
    # Get the notification body from datastore
    jinja2_env = Environment(loader=BaseLoader)
    n_body = jinja2_env.from_string(n_object.get('notification_body', '')).render(**notification_parameters)
    n_title = jinja2_env.from_string(n_object.get('notification_title', '')).render(**notification_parameters)
```</p>
<p>### PoC
1. Create/Edit a URL watch item
2. Under *Notifications* tab insert this payload: 
```python
{{ self.__init__.__globals__.__builtins__.__import__('os').popen('id').read() }}
```
![Screenshot from 2024-04-19 15-46-04](https://github.com/dgtlmoon/changedetection.io/assets/35783570/b6a5779f-fd1e-4708-9b2d-21cb97f0bb4f)</p>
<p>3. See Telegram (or other supported messaging app) notification</p>
<p>![Screenshot from 2024-04-19 16-02-12](https://github.com/dgtlmoon/changedetection.io/assets/35783570/20877919-d6fe-49f1-bbd2-586e900207f1)</p>
<p>### Impact
In the PoC I've used `id` as payload and Telegram to read the result.  
Attacke…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4r7v-whpg-8rx3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-32651</id>
    <title>gsd-2024-32651</title>
    <updated>2026-10-03T20:00:22.687700+00:00</updated>
    <content>gsd-2024-32651</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-32651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-310</id>
    <title>PYSEC-2026-310 — changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution</title>
    <updated>2026-10-03T20:00:22.687714+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: changedetection-io</p>
<p>### Summary
A Server Side Template Injection in changedetection.io caused by usage of unsafe functions of Jinja2 allows Remote Command Execution on the server host.</p>
<p>### Details</p>
<p>changedetection.io version: 0.45.20
```
docker images
REPOSITORY                            TAG       IMAGE ID       CREATED        SIZE
dgtlmoon/changedetection.io           latest    53529c2e69f1   44 hours ago   423MB
 ```</p>
<p>The vulnerability is caused by the usage of vulnerable functions of Jinja2 template engine.
```python
from jinja2 import Environment, BaseLoader
...
    # Get the notification body from datastore
    jinja2_env = Environment(loader=BaseLoader)
    n_body = jinja2_env.from_string(n_object.get('notification_body', '')).render(**notification_parameters)
    n_title = jinja2_env.from_string(n_object.get('notification_title', '')).render(**notification_parameters)
 ```</p>
<p>### PoC
1. Create/Edit a URL watch item
2. Under *Notifications* tab insert this payload: 
```python
{{ self.__init__.__globals__.__builtins__.__import__('os').popen('id').read() }}
```
![Screenshot from 2024-04-19 15-46-04](https://github.com/dgtlmoon/changedetection.io/assets/35783570/b6a5779f-fd1e-4708-9b2d-21cb97f0bb4f)
 
3. See Telegram (or other supported messaging app) notification</p>
<p>![Screenshot from 2024-04-19 16-02-12](https://github.com/dgtlmoon/changedetection.io/assets/35783570/20877919-d6fe-49f1-bbd2-586e900207f1)</p>
<p>### Impact
In the PoC I've used `id` as payload and Telegram to read the result.  
Att…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-310"/>
  </entry>
</feed>
