CVE-2026-95273

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a manipulation of the argument filename can lead to path traversal. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Distinct from CVE-2026-25527, which fixed a different parameter (group) in the same function. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-04: 210-04
Referenced assets3 URLs
Full discourse2 posts
  • Slade 🛡️ LLM Hacker@llm_redteam

    A web page monitor got a path traversal CVE posted today. CVE-2026-95273, CVSS 4.3, in http://changedetection.io up to 0.60.7. The vector is the static_content filename parameter. The post says the exploit is public and no patch exists yet. I have not matched this ID to a GitHub advisory or NVD entry. Treat it as a claim until you do. Until a fixed release ships: 1. Check your version against 0.60.7. 2. Read how the static_content route builds the file path. 3. Keep the UI off the public internet. Put it behind auth or a VPN. A 4.3 score says little about real exposure. What matters is who can reach the UI. #infosec #changedetection

    10020160
    1.3K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters

    CVE-2026-95273: path traversal in dgtlmoon changedetection io up to 0.60.7 via static_content filename, CVSS 4.3, exploit public, no patch. Update or restrict access now. https://www.valtersit.com/cve/CVE-2026-95273/ #CVE #infosec #cybersecurity #dgtlmoon #CVEALERT #CVE #infosec #Linux #XSS #valtersit #snippet #SysAdmin #cybersecurity #devsecops #devops #developer #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #cybersecurityawareness #cybersecuritynews #cybersecuritytips #python #hacker #kali #ubuntu #debian #docker

    0000034
    1.1K followersView on X

Explore more