MEDIUM 5.3 PyPI

CVE-2026-25527

PYSEC-2026-2124 · CVE-2026-25527 · GHSA-9jj8-v89v-xjvw

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the /static/<group>/<filename> route accepts group="..", which causes send_from_directory("static/..", filename) to execute. This moves the base directory up to /app/changedetectionio, enabling unauthenticated local file read of application source files (e.g., flask_app.py). Version 0.53.2 fixes the issue.

Ready to move

Start Securing

Free, no credit card | First findings in minutes