CVE-2026-95656 Details
Description
A vulnerability was found in dgtlmoon changedetection.io up to 50389b07. This vulnerability affects the function add_watch_ui_snapshot of the file changedetectionio/blueprint/add_watch_ui/__init__.py of the component Preview Endpoint. Performing a manipulation of the argument url results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and could be used. Upgrading to version 0.60.1 is able to resolve this issue. The patch is named 71d332d5a0d3da2a0fe89a392413bf4b7d27c84e. The affected component should be upgraded. Was fixed upstream.
A server-side request forgery (SSRF) vulnerability has been identified in Changedetection.io versions up to 50389b07. The issue resides in the 'add_watch_ui_snapshot' function within the 'changedetectionio/blueprint/add_watch_ui/__init__.py' file, specifically in the Preview Endpoint component. The vulnerability allows remote attackers to manipulate the 'url' argument, leading to unauthorized internal network access. This issue has been publicly disclosed and exploited.
Upgrade to Changedetection.io version 0.60.1 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 22, 2026CISA-ADP
Assessed Sep 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/dgtlmoon/changedetection.io/ | [email protected] | Vendor |
| https://github.com/dgtlmoon/changedetection.io/commit/71d332d5a0d3da2a0fe89a392413bf4b7d27c84e | [email protected] | Source CodeVendor |
| https://github.com/dgtlmoon/changedetection.io/releases/tag/0.60.1 | [email protected] | Release NotesVendor |
| https://github.com/herantong/cve/blob/main/changedetection.io_ssrf-preview-endpoint_CWE-918 | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-95656 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/896586 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/408412 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/408412/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dgtlmoon changedetection.io | <= 0.55.8 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | New CVE Received | [email protected] |
| Sep 22, 2026 | CVE Modified | CISA-ADP |
Volerion