GHSA-8whx-v8qq-pq64: changedetection.io has Reflected XSS in its RSS Tag Error Response
mediumvulnerability
security
Summary
changedetection.io versions up to 0.54.1 have a reflected XSS (cross-site scripting, where an attacker injects malicious code into a web page) vulnerability in the `/rss/tag/` endpoint. The vulnerability occurs because user input from the URL is directly inserted into the HTML response without escaping (removing special characters that could be interpreted as code), allowing attackers to inject and execute JavaScript in victims' browsers if they click a malicious link.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Classification
Attack SophisticationTrivial
Affected Packages
changedetection.io@< 0.54.4 (fixed: 0.54.4)
Original source: https://github.com/advisories/GHSA-8whx-v8qq-pq64
First tracked: March 4, 2026 at 07:00 PM
Classified by LLM (prompt v3) · confidence: 95%