Executive brief
changedetection.io is a web monitoring tool that tracks changes to websites. A path traversal vulnerability in its visual selector feature allows an attacker to read arbitrary files from the server by manipulating a filename parameter, potentially exposing sensitive watch data and configuration files.
Technical details
The static_content() function in changedetectionio/flask_app.py fails to sanitize the filename route parameter before passing it to os.path.join() to construct a directory path. When group=visual_selector_data, an attacker can inject path traversal sequences (../) to escape the datastore directory and read elements.deflate files from other watches or system directories. The vulnerability violates Werkzeug's send_from_directory contract which explicitly warns the directory parameter must not be client-supplied.
Affected products
- dgtlmoon changedetection.io up to 0.60.7
Timeline
- 2026-09-22: disclosed: Publicly disclosed vulnerability
- 2026: other: Vendor contacted early but did not respond