Executive brief
changedetection.io is a tool used to monitor websites for changes. A security flaw allows an attacker to read sensitive files from the server's local storage by uploading a specially crafted backup file. This could lead to the exposure of system passwords, configuration files, and private application data.
Technical details
The vulnerability exists in the backup restore logic of changedetection.io. When a backup ZIP is restored, the application extracts and copies watch directories into the live datastore without validating the contents of 'history.txt'. The application's path resolution logic in 'model/Watch.py' fails to enforce a trust boundary; if a history entry contains path separators and the referenced file exists, it is accepted as a valid snapshot path. An attacker can provide a crafted backup containing absolute paths (e.g., /etc/passwd). When a user views the 'Preview' or accesses the history API for that watch, the application performs a direct file read on the attacker-specified path and returns the content. This has been patched in version 0.55.1.
Affected products
- dgtlmoon changedetection.io <= 0.54.10
Timeline
- 2026-04-27: advisory: GitHub Advisory published
- 2026-05-05: disclosed
- 0.55.1: patched