PT-2026-21866 · Unknown · Changedetection.Io
Akokonunes
+1
·
Published
2026-02-25
·
Updated
2026-03-12
·
CVE-2026-27645
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
changedetection.io versions prior to 0.54.1
Description
The application reflects the
UUID path parameter directly in the HTTP response body without HTML escaping in the RSS single-watch endpoint. Because Flask defaults to returning text/html for plain string responses, the browser parses and executes injected JavaScript. This could allow for potential cross-site scripting (XSS) attacks.Recommendations
Update to version 0.54.1 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Changedetection.Io