# CVE-2026-25527: changedetection.io - Path Traversal

> Live exploitation tracking for CVE-2026-25527 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-25527

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 5.3
- **Public exploit available:** Yes
- **Affected products:** Dgtlmoon changedetection.io
- **Weaknesses:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
- **Tags:** web_application, python

## Description

changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This moves the base directory up to `/app/changedetectionio`, enabling unauthenticated local file read of application source files (e.g., `flask_app.py`). Version 0.53.2 fixes the issue.

## CrowdSec analysis

[CVE-2026-25527](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-25527) is a path traversal vulnerability in changedetection.io versions prior to 0.53.2, allowing unauthenticated attackers to read arbitrary local files from the application directory by manipulating the `/static/<group>/<filename>` route. This flaw could expose sensitive source code files, such as `flask_app.py`, potentially aiding further attacks or information disclosure.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

Data from the CrowdSec community indicates that exploitation of CVE-2026-25527 is highly selective and intelligence-driven. Threat actors use advanced reconnaissance and carefully choose their targets, often as part of sophisticated campaigns or advanced persistent threat operations.
CrowdSec network telemetry also shows that exploitation of CVE-2026-25527 has significantly declined over the past week. Attack volumes are well below the long-term average, suggesting attackers are rapidly losing interest. The vulnerability appears to be falling out of active use across most threat landscapes.

Attackers exploit the `/static/../` path traversal vulnerability by manipulating the `group` parameter in the `/static/<group>/<filename>` route to access sensitive local files such as `flask_app.py`.

## Timeline

- 2026-02-19: CVE Published. CVE-2026-25527 is published to NVD.
- 2026-06-24: Rule Released. CrowdSec releases a rule to detect CVE-2026-25527 exploitation attempts against the CrowdSec Network.
- 2026-06-25: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-25527 for the first time.

## References

- https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-9jj8-v89v-xjvw
- https://github.com/dgtlmoon/changedetection.io/commit/9d38b4517364831889b5b0d7b3465fd060403fd4
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-25527.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-25527) follows observed exploitation activity for CVE-2026-25527. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
