GHSA-9jj8-v89v-xjvw: changedetection.io is vulnerable to unauthenticated static path traversal
Summary
The /static/<group>/<filename> route accepts group="..", which causes send_from_directory("static/..", filename) to execute. This moves the base directory up to /app/changedetectionio, enabling unauthenticated local file read of application source files (e.g., flask_app.py). Severity is low information disclosure (C:L).
Details
The vulnerable code is in changedetectionio/flask_app.py inside static_content():
group = re.sub(r'[^\w.-]+', '', group.lower())
filename = re.sub(r'[^\w.-]+', '', filename.lower())
...
return send_from_directory(f"static/{group}", path=filename)
The group sanitization allows dots, so group=".." passes validation.
This results in send_from_directory("static/..", filename), effectively shifting the base directory to /app/changedetectionio and allowing reads of files in that directory.
The route is unauthenticated, so any user can retrieve source files without logging in.
Limitation: the route only matches /static/<group>/<filename> and rejects slashes inside filename, so it cannot traverse further to arbitrary system paths like /etc/passwd. It is limited to files inside the application package directory.
PoC
1) Start an instance (example: Docker on port 5050)
docker run -d --name cdio -p 127.0.0.1:5050:5000 -v cdio-data:/datastore cdio-local
2) Reproduce
(URL-encoded traversal)
curl -i http://127.0.0.1:5050/static/%2e%2e/flask_app.py
(curl path passthrough)
curl --path-as-is -i http://127.0.0.1:5050/static/../flask_app.py
3) Observe that the response body contains Python source code from flask_app.py.
Impact
- Vulnerability type: Directory Traversal / Local File Read
- Affected users: Anyone with network access (no authentication required)
- Scope: Source files under /app/changedetectionio
- Security impact: Internal logic exposure can aid further exploitation (Confidentiality: Low)
Details
Original advisory: https://github.com/advisories/GHSA-9jj8-v89v-xjvw
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-255270.92% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-25527 | coverage & exploitation status | NVD · CVE.org |
More from GitHub Security Advisories
- mediumGHSA-jr6p-8pjj-mfx6: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators s…2026-07-31
- mediumGHSA-68cj-mvg9-rgm2: Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing…2026-07-31
- mediumGHSA-ff84-5f28-78qj: re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex`…2026-07-31
- mediumGHSA-6hxr-mr5r-9836: re2: Global `String.prototype.match` with an empty-matchable pattern never advances → inf…2026-07-31
- mediumGHSA-x83g-979r-f5fh: Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII2026-07-31