CVE-2026-71203 PUBLISHED

changedetection.io: Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Schema

Assigner: TuranSec
Reserved: 05.08.2026 Published: 05.08.2026 Updated: 05.08.2026

changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get() method carries neither @auth.check_token nor @validate_openapi_request. An unauthenticated client can retrieve the full merged OpenAPI schema (all endpoint paths, parameters, and registered processor plugins) even when API access control is enabled and every sibling /api/v1/* route correctly requires the key.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor dgtlmoon
Product changedetection.io
Versions Default: unknown
  • Version 0.55.7 is affected

Credits

  • Eldor Nabijonov finder

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE