CVE-2026-95273 | dgtlmoon changedetection.io up to 0.60.7 visual_selector_data flask_app.py static_content filename path traversal

SecurityVulns

A vulnerability, which was classified as problematic, was found in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a manipulation of the argument filename can lead to path traversal.

This vulnerability is registered as CVE-2026-95273. It is possible to launch the attack remotely. Furthermore, an exploit is available.

Distinct from CVE-2026-25527, which fixed a different parameter (group) in the same function. The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More