CVE-2026-95656 | dgtlmoon changedetection.io up to 50389b07 Preview Endpoint __init__.py add_watch_ui_snapshot url server-side request forgery
A vulnerability has been found in dgtlmoon changedetection.io up to 50389b07 and classified as critical. This vulnerability affects the function add_watch_ui_snapshot of the file changedetectionio/blueprint/add_watch_ui/__init__.py of the component Preview Endpoint. Performing a manipulation of the argument url results in server-side request forgery.
This vulnerability is identified as CVE-2026-95656. The attack can be initiated remotely. Additionally, an exploit exists.
The affected component should be upgraded.
Was fixed upstream.VulDB Recent EntriesRead More