Executive brief
changedetection.io, a tool used to monitor website changes, contains a flaw that allows anyone to bypass login requirements on several critical pages. An attacker can use this to download full system backups containing sensitive data like passwords and API tokens, or even delete existing backups. This could lead to a total compromise of the monitoring service and any connected accounts.
Technical details
An authentication bypass exists in changedetection.io due to the incorrect ordering of Flask decorators on 13 specific routes. In the affected code, the `@login_optionally_required` decorator was placed outside the `@blueprint.route()` decorator; because Flask's `@route` registers the function it immediately wraps, it registered the raw, unprotected view function instead of the decorated one. A remote, unauthenticated attacker can exploit this to access endpoints such as `/backups/`, `/backups/download/<filename>`, and `/backups/remove-backups`. This allows for full data exfiltration (including password hashes and notification tokens), SSRF via proxy checks, and potential configuration injection. The issue is fixed in version 0.54.8 by swapping the decorator order.
Affected products
- dgtlmoon changedetection.io <= 0.54.7
Timeline
- 2026-04-04: disclosed: Initial disclosure by dgtlmoon
- 2026-04-06: advisory: GitHub Advisory published
- 2026-04-07: other: NVD publication date