GHSA-4jg2-g9g4-7fppHighCVSS 7.5

changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps,...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to retrieve responses from restricted network locations.

🔗 References (6)