PatchSiren

dgtlmoon CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM dgtlmoon CVE published 2026-08-05

CVE-2026-71205

changedetection.io's /login route is vulnerable to brute-force attacks due to the lack of rate limiting and use of a single PBKDF2-HMAC-SHA256 hash for password checking. Successful brute-force guesses grant full administrative access. The vulnerability affects changedetection.io instances, which are protected by a shared password with no per-user accounts. Administrators and users should be aware of the [truncated]

MEDIUM dgtlmoon CVE published 2026-08-05

CVE-2026-71204

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T08:16:42.327Z and has not been modified since then. The vulnerability, CVE-2026-71204, exists in changedetection.io's /settings save handler, which blind-merges form data into stored application settings. This could lead to the disabling of API key enforcement via a minimal scripted request, pote [truncated]

MEDIUM dgtlmoon CVE published 2026-08-05

CVE-2026-71203

changedetection.io's REST API resource at /api/v1/full-spec lacks authentication validation, allowing unauthenticated clients to retrieve the full merged OpenAPI schema when API access control is enabled. This vulnerability affects the changedetection.io platform, and defenders should review the API access controls and authentication mechanisms. The technical impact is medium, and the source-grounded tech [truncated]

HIGH dgtlmoon CVE published 2026-04-01

CVE-2026-35000

ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation. This vulnerability allows attackers to read arbitrary local files by using unblocked XPath 3.0/3.1 functions such as json-doc() and similar file-access primitives. The vulnerability exists due to an incomplete blocklist of dangerous XPath functions, enabling attackers to access sen [truncated]