
A web page monitor got a path traversal CVE posted today. CVE-2026-95273, CVSS 4.3, in http://changedetection.io up to 0.60.7. The vector is the static_content filename parameter. The post says the exploit is public and no patch exists yet. I have not matched this ID to a GitHub advisory or NVD entry. Treat it as a claim until you do. Until a fixed release ships: 1. Check your version against 0.60.7. 2. Read how the static_content route builds the file path. 3. Keep the UI off the public internet. Put it behind auth or a VPN. A 4.3 score says little about real exposure. What matters is who can reach the UI. #infosec #changedetection

