
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27645 is a reflected cross-site scripting (XSS) vulnerability in changedetection.io, a free open-source web page change detection tool. The flaw exists in the RSS single-watch endpoint, which reflects the UUID path parameter directly in the HTTP response body without HTML escaping, allowing injected JavaScript to execute in the victim's browser. All versions up to and including 0.53.6 are affected; the issue was disclosed on February 23, 2026, and patched in version 0.54.1 (released February 25, 2026). It carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Security Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation). In changedetectionio/blueprint/rss/single_watch.py, the UUID path parameter is interpolated directly into error response strings using Python f-strings with no HTML escaping (e.g., return f"Watch with UUID {uuid} not found", 404). Because Flask's default Content-Type for plain string responses is text/html; charset=utf-8, the browser parses and executes any HTML or JavaScript embedded in the UUID. Exploitation additionally requires a valid RSS access token — a 32-character hex string that is exposed in an HTML tag on the homepage and is accessible without authentication, significantly lowering the barrier to attack (Security Advisory, Patch Commit).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser within the context of the changedetection.io application. This can lead to session cookie theft (via document.cookie exfiltration), full account takeover if session cookies lack the HttpOnly flag, unauthorized actions performed on behalf of the victim, and phishing attacks via crafted links that appear to originate from a trusted instance. The vulnerability was validated at scale against 500 internet-facing instances discovered via FOFA, producing over 5,000 confirmed detections, demonstrating widespread real-world exposure (Security Advisory, GitHub Advisory).
A public proof-of-concept is available in the GitHub security advisory, including a working PoC HTTP request. The vulnerability was validated against 500 internet-facing instances using a custom Nuclei template, though there is no confirmed evidence of active in-the-wild exploitation by threat actors at this time. The EPSS score is approximately 0.715% (73rd percentile), indicating a moderate probability of exploitation within 30 days. The vulnerability is not currently listed in the CISA KEV catalog (GitHub Advisory, Security Advisory).
<meta> or similar tag).http://target:5000/rss/watch/%3Cimg%20src%3Dx%20onerror%3Dalert(document.cookie)%3E?token=<EXTRACTED_TOKEN>Watch with UUID <img src=x onerror=alert(document.cookie)> not found. The browser renders the HTML and executes the JavaScript.alert(document.cookie) payload with a script that exfiltrates session cookies to an attacker-controlled server, enabling session hijacking and account takeover (Security Advisory, GitHub Advisory)./rss/watch/<non-UUID-string> with URL-encoded HTML/JavaScript characters (e.g., %3C, %3E, onerror, script) in the path parameter./rss/watch/ with URL-encoded XSS payloads in the UUID segment (e.g., %3Cimg, %3Cscript, onerror); 404 or 400 HTTP responses to such requests indicating the payload was reflected.Upgrade changedetection.io to version 0.54.1 or later, which fixes the issue by changing the response to use flask.Response with mimetype='text/plain' and properly escaping the UUID parameter via flask_babel's lazy_gettext, preventing HTML rendering (Patch Commit). For systems that cannot be immediately patched, restrict network access to the RSS single-watch endpoint (/rss/watch/) or deploy a web application firewall (WAF) rule to block requests containing URL-encoded HTML characters in the UUID path segment. Additionally, educate users to avoid clicking on unsolicited links purportedly from their changedetection.io instance (GitHub Advisory).
The vulnerability was reported by security researchers Roberto Nunes (Akokonunes) and neo-ai-engineer, who validated it at scale against 500 internet-facing instances using a custom Nuclei template. The ProjectDiscovery Nuclei templates repository received multiple commits adding detection templates for CVE-2026-27645, indicating active community interest in automated detection. The vulnerability was also picked up by INCIBE-CERT and Red Hat's security advisory feeds, and noted on Bluesky by CVE tracking accounts (Security Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."