Three security vulnerabilities were identified in changedetection.io through source code review and live validation against a locally deployed Docker instance. All vulnerabilities were confirmed exploitable on the latest version (0.53.6) it was additionally validated at scale against 500 internet-facing instances discovered via FOFA search engine, producing 5K+ confirmed detections using a custom Nuclei template, demonstrating widespread real-world impact. The RSS single-watch endpoint reflects the UUID path parameter directly in the HTTP response body without HTML escaping. Since Flask returns text/html by default for plain string responses, the browser parses and executes injected JavaScript.
File: changedetectionio/blueprint/rss/single_watch.py (lines ~45 and ~50)
The UUID parameter from the URL path is interpolated into the response body using an f-string with no escaping:
watch = datastore.data['watching'].get(uuid)
if not watch:
return f"Watch with UUID {uuid} not found", 404 # ← No escaping, Content-Type: text/html
if len(dates) < 2:
return f"Watch {uuid} does not have enough history snapshots...", 400 # ← Same issue
Flask's default Content-Type for plain string responses is text/html; charset=utf-8, so any HTML/JavaScript in {uuid} is rendered by the browser.
The attack requires a valid RSS access token, which is a 32-character hex string exposed in the HTML tag on the homepage without authentication:
Attacker visits the target's homepage if it unauthenticathed and extracts the RSS token from the tag Crafts a malicious URL:
The browser renders the tag, the onerror fires, and JavaScript executes in the victim's session context
Request:
GET /rss/watch/%3Cimg%20src%3Dx%20onerror%3Dalert(document.cookie)%3E?token=223e7edbbfee2268f5abb5344919054e HTTP/1.1
Host: [127.0.0.1:5000](http://127.0.0.1:5000/)
Response:
HTTP/1.1 404 NOT FOUND
Content-Type: text/html; charset=utf-8
Watch with UUID not found
The XSS payload is reflected unescaped in an HTML response. The browser executes alert(document.cookie).
Lots of intances over internet affected to this.
changedetection.io can work with developer teams to validate and address these issues. Please confirm receipt of this report and inform changedetection.io of the preferred timeline for coordinating the fix.
Roberto Nunes
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-25T19:07:44Z",
"nvd_published_at": "2026-02-25T05:17:26Z",
"severity": "MODERATE"
}