Junglewise Threat Intelligence

CVE-2025-62780: changedetection.io Stored XSS in Watch update via API

CVE-2025-62780 · Severity: low · CVSS 3.5 · Published 2025-11-12

Technologies: changedetection.io (PyPI), Dgtlmoon Changedetection.Io. Vendors: PyPI, Dgtlmoon.

Executive brief

changedetection.io is a tool used to monitor websites for changes. A security flaw allows an attacker with API access to inject malicious scripts into the system by bypassing URL safety checks. If an administrator previews a compromised monitor, the script could execute in their browser, potentially leading to unauthorized actions or data theft.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in changedetection.io due to inconsistent input validation between the web UI and the API. While the UI correctly validates URLs using the `validate_url` function and `is_safe_url` check, the Watch update API (v1) fails to perform these checks. An attacker with a valid API key can update a watch's URL to a 'javascript:' payload. When a user subsequently interacts with the 'Preview' link for that watch in the web interface, the malicious JavaScript is executed in the context of the user's session. This issue is fixed in version 0.50.34.

Affected products

  • dgtlmoon changedetection.io < 0.50.34

Timeline

  • 2025-11-10: disclosed
  • 2025-11-10: patched: Version 0.50.34 released
  • 2025-11-12: advisory

References

Related threats