Executive brief
changedetection.io is a web monitoring tool that fetches and tracks changes to web pages. The vulnerability allows unauthenticated users (since no password is set by default) to monitor internal network addresses like 169.254.169.254 (which serves cloud provider credentials), forcing the application to fetch and store sensitive data from internal infrastructure. This enables attackers to exfiltrate secrets, credentials, and other sensitive information without authentication.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) caused by incomplete URL validation in the is_safe_valid_url() function (changedetectionio/validate_url.py:60–122), which checks only protocol and URL format but performs no IP address validation against private, loopback, or link-local ranges. An attacker can add a watch targeting internal URLs (http://169.254.169.254, http://10.0.0.1/, http://127.0.0.1/) via the web UI, REST API, or import API. The application then fetches these URLs server-side without additional validation, stores the full response content, and displays it in the web UI—making this a non-blind, persistent SSRF. No authentication is required by default. The fix is available in version 0.54.1; affected versions are <= 0.53.1.
Affected products
- dgtlmoon changedetection.io <= 0.53.1
Timeline
- 2026-02-25: disclosed: GHSA-3c45-4pj5-ch7m published
- 2026: patched: Fixed in version 0.54.1