CVE-2026-95656 | dgtlmoon changedetection.io up to 50389b07 Preview Endpoint __init__.py add_watch_ui_snapshot url server-side request forgery

SecurityVulns

A vulnerability has been found in dgtlmoon changedetection.io up to 50389b07 and classified as critical. This vulnerability affects the function add_watch_ui_snapshot of the file changedetectionio/blueprint/add_watch_ui/__init__.py of the component Preview Endpoint. Performing a manipulation of the argument url results in server-side request forgery.

This vulnerability is identified as CVE-2026-95656. The attack can be initiated remotely. Additionally, an exploit exists.

The affected component should be upgraded.

Was fixed upstream.VulDB Recent EntriesRead More