PT-2026-21866 · Unknown · Changedetection.Io

Akokonunes

+1

·

Published

2026-02-25

·

Updated

2026-03-12

·

CVE-2026-27645

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions changedetection.io versions prior to 0.54.1
Description The application reflects the UUID path parameter directly in the HTTP response body without HTML escaping in the RSS single-watch endpoint. Because Flask defaults to returning text/html for plain string responses, the browser parses and executes injected JavaScript. This could allow for potential cross-site scripting (XSS) attacks.
Recommendations Update to version 0.54.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27645
GHSA-MW8M-398G-H89W

Affected Products

Changedetection.Io