Junglewise Threat Intelligence

CVE-2026-95656: dgtlmoon changedetection.io server-side request forgery in preview endpoint

CVE-2026-95656 · Severity: high · CVSS 7.3 · Published 2026-09-22

Technologies: Dgtlmoon Changedetection.Io. Vendors: Dgtlmoon.

Executive brief

changedetection.io is a web monitoring tool that tracks website changes and alerts users to modifications. A flaw in the preview endpoint allows attackers to manipulate the URL parameter to perform server-side request forgery (SSRF), enabling them to make the server access internal resources or external systems on behalf of the attacker. This could lead to unauthorized data access or facilitate further attacks against internal infrastructure.

Technical details

The vulnerability exists in the add_watch_ui_snapshot function within changedetectionio/blueprint/add_watch_ui/__init__.py, where insufficient input validation on the URL parameter allows SSRF. An attacker can send a crafted request remotely to manipulate the server into making requests to arbitrary destinations. The issue has been patched in version 0.60.1 (commit 71d332d5a0d3da2a0fe89a392413bf4b7d27c84e).

Affected products

  • dgtlmoon changedetection.io up to 0.60.1

Timeline

  • 2026-09-22: disclosed: Vulnerability publicly disclosed
  • 2026-07-16: patched: Fixed in version 0.60.1 via commit 71d332d5a0d3da2a0fe89a392413bf4b7d27c84e

References

Related threats