In changedetection.io versions prior to 0.53.2 a medium severity vulnerability CVE-2026-25527 was detected. This vulnerability allows unauthenticated attackers to read arbitrary local application files via a path traversal flaw in the `/static/<group>/<filename>` route, due to improper validation of the group parameter. To address this issue, users should upgrade changedetection.io to version 0.53.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25527.