changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() instead of after it. In Flask, @route() must be the outermost decorator because it registers the function it receives. When the order is reversed, @route() registers the original undecorated function, and the auth wrapper is never in the call chain. This silently disables authentication on these routes. This vulnerability is fixed in 0.54.8.
References
| Link | Resource |
|---|---|
| https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-jmrh-xmgh-x9j4 | Exploit Mitigation Vendor Advisory |
| https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-jmrh-xmgh-x9j4 | Exploit Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-04-07 16:16
Updated : 2026-06-17 10:40
NVD link : CVE-2026-35490
Mitre link : CVE-2026-35490
CVE.ORG link : CVE-2026-35490
JSON object : View
Products Affected
webtechnologies
- changedetection
CWE
CWE-863
Incorrect Authorization
