<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:10:10.247498+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-25527</id>
    <title>CVE-2026-25527 — changedetection.io vulnerable to unauthenticated static path traversal</title>
    <updated>2026-10-02T21:10:10.288741+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> dgtlmoon changedetection.io</p>
<p>changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/&lt;group&gt;/&lt;filename&gt;` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This moves the base directory up to `/app/changedetectionio`, enabling unauthenticated local file read of application source files (e.g., `flask_app.py`). Version 0.53.2 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-25527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9jj8-v89v-xjvw</id>
    <title>GHSA-9jj8-v89v-xjvw — changedetection.io is vulnerable to unauthenticated static path traversal</title>
    <updated>2026-10-02T21:10:10.288811+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: changedetection.io</p>
<p>## Summary
The `/static/&lt;group&gt;/&lt;filename&gt;` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This moves the base directory up to `/app/changedetectionio`, enabling **unauthenticated local file read** of application source files (e.g., `flask_app.py`). Severity is **low information disclosure (C:L)**.</p>
<p>### Details
The vulnerable code is in `changedetectionio/flask_app.py` inside `static_content()`:</p>
<p>```
group = re.sub(r'[^\w.-]+', '', group.lower())
filename = re.sub(r'[^\w.-]+', '', filename.lower())
...
return send_from_directory(f"static/{group}", path=filename)
```</p>
<p>The `group` sanitization allows dots, so `group=".."` passes validation.  
This results in `send_from_directory("static/..", filename)`, effectively shifting the base directory to `/app/changedetectionio` and allowing reads of files in that directory.  
The route is unauthenticated, so **any user can retrieve source files** without logging in.</p>
<p>&gt; Limitation: the route only matches `/static/&lt;group&gt;/&lt;filename&gt;` and rejects slashes inside `filename`, so it cannot traverse further to arbitrary system paths like `/etc/passwd`. It is limited to files inside the application package directory.</p>
<p>### PoC
1) Start an instance (example: Docker on port 5050)
```
docker run -d --name cdio -p 127.0.0.1:5050:5000 -v cdio-data:/datastore cdio-local
```</p>
<p>2) Reproduce  
**(URL-encoded traversal)**
```
curl -i http://127.0.0.1:5050/static/%2e%2e/flask_app.py
```</p>
<p>**(curl path passt…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9jj8-v89v-xjvw"/>
  </entry>
</feed>
