CVE-2026-27645

changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, the RSS single-watch endpoint reflects the UUID path parameter directly in the HTTP response body without HTML escaping. Since Flask returns text/html by default for plain string responses, the browser parses and executes injected JavaScript. Version 0.54.1 contains a fix for the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:webtechnologies:changedetection:*:*:*:*:*:*:*:*

History

25 Feb 2026, 16:51

Type Values Removed Values Added
First Time Webtechnologies changedetection
Webtechnologies
References () https://github.com/dgtlmoon/changedetection.io/commit/a385c89abf44b52fcfa20c7c6a6dd3047c4c1eb5 - () https://github.com/dgtlmoon/changedetection.io/commit/a385c89abf44b52fcfa20c7c6a6dd3047c4c1eb5 - Patch
References () https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-mw8m-398g-h89w - () https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-mw8m-398g-h89w - Exploit, Vendor Advisory
CPE cpe:2.3:a:webtechnologies:changedetection:*:*:*:*:*:*:*:*

25 Feb 2026, 15:20

Type Values Removed Values Added
References () https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-mw8m-398g-h89w - () https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-mw8m-398g-h89w -

25 Feb 2026, 14:15

Type Values Removed Values Added
Summary
  • (es) changedetection.io es una herramienta gratuita de código abierto para la detección de cambios en páginas web. En versiones anteriores a la 0.54.1, el endpoint RSS de monitoreo único refleja el parámetro de ruta UUID directamente en el cuerpo de la respuesta HTTP sin escape HTML. Dado que Flask devuelve text/html por defecto para respuestas de cadena de texto plano, el navegador analiza y ejecuta JavaScript inyectado. La versión 0.54.1 contiene una corrección para el problema.

25 Feb 2026, 05:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 05:17

Updated : 2026-02-25 16:51


NVD link : CVE-2026-27645

Mitre link : CVE-2026-27645

CVE.ORG link : CVE-2026-27645


JSON object : View

Products Affected

webtechnologies

  • changedetection
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')