CVE-2026-92814 Overview
CVE-2026-92814 is a stored HTML/markup injection vulnerability in changedetection.io through version 0.60.6. The application fails to escape the scraped page title before rendering it inside HTML notifications. When a template uses the watch_title token, attacker-controlled markup from a monitored page title reaches downstream notification channels such as email and Telegram as live content. This weakness is tracked under [CWE-79] (Improper Neutralization of Input During Web Page Generation).
Critical Impact
Attackers who control a monitored page title can inject arbitrary HTML into notifications delivered to operators, enabling phishing content, tracking pixels, or client-side rendering abuse.
Affected Products
- changedetection.io versions up to and including 0.60.6
- Deployments using HTML notification templates that reference the watch_title token
- Notification integrations that render HTML content, including email and Telegram HTML mode
Discovery Timeline
- 2026-09-16 - CVE-2026-92814 published to the National Vulnerability Database (NVD)
- 2026-09-16 - Last updated in NVD database
Technical Details for CVE-2026-92814
Vulnerability Analysis
The flaw resides in the notification handler that assembles HTML-formatted alerts. According to the referenced code in changedetectionio/notification/handler.py, the watch_title value is substituted into HTML notification bodies without being added to the escape set applied to other user-controlled tokens.
Because watch_title is derived from the scraped page's <title> element, any attacker who controls a monitored resource controls the value substituted into the notification. When the notification is rendered by an HTML-capable client, the injected markup executes as content rather than text. Additional detail is available in the security finding report and the VulnCheck advisory.
Root Cause
The root cause is inconsistent output encoding. The notification builder maintains an escape set for template tokens but omits watch_title. Tokens outside the escape set are inserted verbatim into HTML output, violating the principle of contextual encoding for all untrusted values.
Attack Vector
An attacker seeds malicious markup into the <title> element of a page monitored by a target changedetection.io instance. When the watcher next polls the page and dispatches a notification using an HTML template containing {{watch_title}}, the crafted markup is delivered inline to every configured notification recipient. Exploitation requires user interaction (opening the notification) and template configuration that references watch_title.
No verified proof-of-concept code is published in the advisory references. See the linked GitHub finding report for technical details.
Detection Methods for CVE-2026-92814
Indicators of Compromise
- Notification emails or Telegram messages containing unexpected HTML tags such as <script>, <img>, <a>, or <iframe> inside the page title field.
- Watch entries whose stored titles contain angle brackets, event handler attributes, or URL-bearing markup rather than plain text.
- Outbound requests from mail clients to unfamiliar domains shortly after processing a changedetection.io alert, suggesting rendered tracking pixels or beacons.
Detection Strategies
- Inspect the changedetection.io datastore for watches where the stored title contains HTML metacharacters (<, >, ", ') and validate them against the source page.
- Run content inspection on outbound notification traffic to flag HTML notifications whose title field deviates from a plain-text pattern.
- Correlate newly added or recently modified watches against title values that fail an HTML-safe regex to prioritize review.
Monitoring Recommendations
- Log every dispatched notification with the raw watch_title value and alert on entries containing markup characters.
- Monitor the version of deployed changedetection.io instances and flag any still running 0.60.6 or earlier.
- Track user reports of malformed or suspicious notifications as a leading signal of exploitation.
How to Mitigate CVE-2026-92814
Immediate Actions Required
- Upgrade changedetection.io to a release later than 0.60.6 that includes escaping for the watch_title token; consult the project repository for the current fixed version.
- Audit existing notification templates and temporarily remove the {{watch_title}} token from HTML notification bodies until patched.
- Review the list of monitored URLs and remove any watches pointing to untrusted or attacker-influenced pages.
Patch Information
At the time of publication, the NVD entry does not enumerate a fixed version. Administrators should track the changedetection.io GitHub repository for a release that adds watch_title to the notification escape set and apply it promptly.
Workarounds
- Switch notification templates to plain-text format, which does not render injected HTML markup.
- For Telegram integrations, disable HTML parse mode so raw markup is delivered as text.
- Restrict changedetection.io to monitoring only trusted, first-party URLs to reduce the attack surface for title-based injection.
# Example: pull the latest patched image once released
docker pull ghcr.io/dgtlmoon/changedetection.io:latest
docker stop changedetection && docker rm changedetection
docker run -d --name changedetection \
-p 5000:5000 \
-v datastore-volume:/datastore \
ghcr.io/dgtlmoon/changedetection.io:latest
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.