{"id":"CVE-2026-71203","published":"2026-08-05T08:16:42.203","lastModified":"2026-08-10T12:17:24.040","description":"changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method carries neither @auth.check_token nor @validate_openapi_request.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwes":["CWE-306"],"vendors":[],"products":[],"references":[{"url":"https://github.com/dgtlmoon/changedetection.io","tags":[]}],"exploitRefs":[{"url":"https://github.com/dgtlmoon/changedetection.io","tags":[]}],"hasPoc":true,"ai":null}