HIGH 8.7 NVD
CVE-2026-92815
changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attac
changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to retrieve responses from restricted network locations.
References
- https://github.com/dgtlmoon/changedetection.io
- https://github.com/dgtlmoon/changedetection.io/blob/0.60.6/changedetectionio/browser_steps
- https://github.com/geo-chen/oss/blob/main/changedetection.io.md#finding-2-ssrf-via-browser
- https://www.vulncheck.com/advisories/changedetection-io-through-0.60.6-ssrf-via-browser-st
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-16 via NVD.
vulnfeed aggregates 14597 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.