CVE-2026-92815
EUVD-2026-8107316.09.2026, 21:17
changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to retrieve responses from restricted network locations.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References