rootpwn

high · CVSS v3 7.5 · CVSS v4 8.7

CVE-2026-92815

changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attac…

Description

changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to retrieve responses from restricted network locations.

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
8.7
EPSS

← All CVEs