changedetection.io - Path Traversal (CVE-2026-25527)
Description
changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the /static/<group>/<filename> route accepts group="..", which causes send_from_directory("static/..", filename) to execute. This moves the base directory up to /app/changedetectionio, enabling unauthenticated local file read of application source files (e.g., flask_app.py). Version 0.53.2 fixes the issue.
psychologyCrowdSec Analysis
CVE-2026-25527 is a path traversal vulnerability in changedetection.io versions prior to 0.53.2, allowing unauthenticated attackers to read arbitrary local files from the application directory by manipulating the /static/<group>/<filename> route. This flaw could expose sensitive source code files, such as flask_app.py, potentially aiding further attacks or information disclosure.
CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.
Data from the CrowdSec community indicates that exploitation of CVE-2026-25527 is highly selective and intelligence-driven. Threat actors use advanced reconnaissance and carefully choose their targets, often as part of sophisticated campaigns or advanced persistent threat operations. CrowdSec network telemetry also shows that exploitation of CVE-2026-25527 has significantly declined over the past week. Attack volumes are well below the long-term average, suggesting attackers are rapidly losing interest. The vulnerability appears to be falling out of active use across most threat landscapes.
Attackers exploit the /static/../ path traversal vulnerability by manipulating the group parameter in the /static/<group>/<filename> route to access sensitive local files such as flask_app.py.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2026-02-19 |
| Rule Released | 2026-06-24 |
| CrowdSec First Seen | 2026-06-25 |