{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/changedetection.io--0.60.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:changedetection_io:changedetection_io:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-92815"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["changedetection.io (\u003c= 0.60.6)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","ssrf"],"_cs_type":"advisory","_cs_vendors":["changedetection.io"],"content_html":"\u003cp\u003echangedetection.io versions up to and including 0.60.6 are susceptible to a Server-Side Request Forgery (SSRF) vulnerability identified as CVE-2026-92815. The flaw resides in the handling of the 'Goto URL' action within browser steps. By manipulating the 'optional_value' parameter, an unauthenticated attacker can force the application to make HTTP requests to arbitrary internal IP addresses or services that are otherwise unreachable from the public internet. This allows for the discovery of internal infrastructure, unauthorized access to internal web services, and potential data exfiltration of internal-only content. Defenders should identify instances of changedetection.io and restrict the service's ability to initiate connections to sensitive internal networks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated actors to bypass network perimeter controls to probe internal resources. This can lead to the exposure of sensitive internal service configurations, metadata, or data contained within an organization's private network segment that the changedetection.io instance has network visibility into.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all affected changedetection.io instances to a version later than 0.60.6. Implement network-level egress filtering to restrict the changedetection.io service container or host from reaching private IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and sensitive management interfaces.\u003c/p\u003e\n","date_modified":"2026-09-16T21:58:13Z","date_published":"2026-09-16T21:58:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-changedetection-ssrf/","summary":"changedetection.io versions 0.60.6 and earlier contain a Server-Side Request Forgery (SSRF) vulnerability allowing unauthenticated attackers to access internal network resources.","title":"SSRF Vulnerability in changedetection.io","url":"https://feed.craftedsignal.io/briefs/2026-09-changedetection-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Changedetection.io (\u003c= 0.60.6)","version":"https://jsonfeed.org/version/1.1"}