CVE-2026-27645: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-27645 is a reflected cross-site scripting (XSS) vulnerability in changedetection.io, a free open-source web page change detection tool. The flaw exists in the RSS single-watch endpoint, which reflects the UUID path parameter directly in the HTTP response body without HTML escaping, allowing injected JavaScript to execute in the victim's browser. All versions up to and including 0.53.6 are affected; the issue was disclosed on February 23, 2026, and patched in version 0.54.1 (released February 25, 2026). It carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Security Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation). In changedetectionio/blueprint/rss/single_watch.py, the UUID path parameter is interpolated directly into error response strings using Python f-strings with no HTML escaping (e.g., return f"Watch with UUID {uuid} not found", 404). Because Flask's default Content-Type for plain string responses is text/html; charset=utf-8, the browser parses and executes any HTML or JavaScript embedded in the UUID. Exploitation additionally requires a valid RSS access token — a 32-character hex string that is exposed in an HTML tag on the homepage and is accessible without authentication, significantly lowering the barrier to attack (Security Advisory, Patch Commit).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser within the context of the changedetection.io application. This can lead to session cookie theft (via document.cookie exfiltration), full account takeover if session cookies lack the HttpOnly flag, unauthorized actions performed on behalf of the victim, and phishing attacks via crafted links that appear to originate from a trusted instance. The vulnerability was validated at scale against 500 internet-facing instances discovered via FOFA, producing over 5,000 confirmed detections, demonstrating widespread real-world exposure (Security Advisory, GitHub Advisory).

Exploitability

A public proof-of-concept is available in the GitHub security advisory, including a working PoC HTTP request. The vulnerability was validated against 500 internet-facing instances using a custom Nuclei template, though there is no confirmed evidence of active in-the-wild exploitation by threat actors at this time. The EPSS score is approximately 0.715% (73rd percentile), indicating a moderate probability of exploitation within 30 days. The vulnerability is not currently listed in the CISA KEV catalog (GitHub Advisory, Security Advisory).

Exploitation steps

  1. Reconnaissance: Use FOFA, Shodan, or Censys to identify internet-facing changedetection.io instances running versions ≤ 0.53.6.
  2. Extract RSS token: Visit the target's homepage (which may be unauthenticated) and extract the 32-character hex RSS access token from the HTML source (exposed in a <meta> or similar tag).
  3. Craft malicious URL: Construct a URL with an XSS payload in the UUID path parameter, e.g.:
    http://target:5000/rss/watch/%3Cimg%20src%3Dx%20onerror%3Dalert(document.cookie)%3E?token=<EXTRACTED_TOKEN>
  4. Deliver the link: Send the crafted URL to a victim who has an active authenticated session on the changedetection.io instance (e.g., via email, chat, or phishing).
  5. Trigger execution: When the victim clicks the link, the server responds with a 404 error containing the unescaped payload: Watch with UUID <img src=x onerror=alert(document.cookie)> not found. The browser renders the HTML and executes the JavaScript.
  6. Achieve objective: Replace the alert(document.cookie) payload with a script that exfiltrates session cookies to an attacker-controlled server, enabling session hijacking and account takeover (Security Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from a victim's browser to an attacker-controlled domain shortly after accessing a changedetection.io RSS endpoint; unusual GET requests to /rss/watch/<non-UUID-string> with URL-encoded HTML/JavaScript characters (e.g., %3C, %3E, onerror, script) in the path parameter.
  • Logs: Web server access logs showing requests to /rss/watch/ with URL-encoded XSS payloads in the UUID segment (e.g., %3Cimg, %3Cscript, onerror); 404 or 400 HTTP responses to such requests indicating the payload was reflected.
  • File System: No direct file system artifacts expected for reflected XSS; however, monitor for unexpected new session tokens or API keys generated after a suspected exploitation event.
  • Process/Application: Unexpected session invalidations or new logins from unfamiliar IP addresses following a user clicking an external link to the changedetection.io instance (Security Advisory).

Mitigation and workarounds

Upgrade changedetection.io to version 0.54.1 or later, which fixes the issue by changing the response to use flask.Response with mimetype='text/plain' and properly escaping the UUID parameter via flask_babel's lazy_gettext, preventing HTML rendering (Patch Commit). For systems that cannot be immediately patched, restrict network access to the RSS single-watch endpoint (/rss/watch/) or deploy a web application firewall (WAF) rule to block requests containing URL-encoded HTML characters in the UUID path segment. Additionally, educate users to avoid clicking on unsolicited links purportedly from their changedetection.io instance (GitHub Advisory).

Community reactions

The vulnerability was reported by security researchers Roberto Nunes (Akokonunes) and neo-ai-engineer, who validated it at scale against 500 internet-facing instances using a custom Nuclei template. The ProjectDiscovery Nuclei templates repository received multiple commits adding detection templates for CVE-2026-27645, indicating active community interest in automated detection. The vulnerability was also picked up by INCIBE-CERT and Red Hat's security advisory feeds, and noted on Bluesky by CVE tracking accounts (Security Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management