CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-25527

mediumCVSS 5.3covered by 1 sourcefirst seen 2026-07-20
Summary The /static/<group>/<filename> route accepts group="..", which causes send_from_directory("static/..", filename) to execute. This moves the base directory up to /app/changedetectionio, enabling unauthenticated local file read of application source files (e.g., flask_app.py). Severity is low information disclosure (C:L). Details The vulnerable code is in changedetectionio/flask_app.py inside static_content(): group = re.sub(r'[^\w.-]+', '', group.lower()) filename = re.sub(r'[^\w.-]+', '', filename.lower()) ... return send_from_directory(f"static/{group}", path=filename) The group sanitization allows dots, so group=".." passes validation. This results in send_from_directory("static/..", filename), effectively shifting the base directory to /app/changedetectionio and allowing reads of files in that directory. The route is unauthenticated, so any user can retrieve source files without logging in. Limitation: the route only matches /static/<group>/<filename> and rejects slashes inside filename, so it cannot traverse further to arbitrary system paths like /etc/passwd. It is limited to files inside the application package directory. PoC 1) Start an instance (example: Docker on port 5050) docker run -d --name cdio -p 127.0.0.1:5050:5000 -v cdio-data:/datastore cdio-local 2) Reproduce (URL-encoded traversal) curl -i http://127.0.0.1:5050/static/%2e%2e/flask_app.py (curl path passthrough) curl --path-as-is -i http://127.0.0.1:5050/static/../flask_app.py 3) Observe that the response body contains Python source code from flask_app.py. Impact - Vulnerability type: Directory Traversal / Local File Read - Affected users: Anyone with network access (no authentication required) - Scope: Source files under /app/changedetectionio - Security impact: Internal logic exposure can aid further exploitation (Confidentiality: Low)

⚡ Watch CVE-2026-25527

Get an email if CVE-2026-25527 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-25527

CVE.org record

Embed the live status

CVE-2026-25527 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-25527 status](https://www.csirts.com/badge/CVE-2026-25527)](https://www.csirts.com/cve/CVE-2026-25527)