๐Ÿ” CVE Alert

CVE-2026-29039

UNKNOWN 0.0

changedetection.io: XPath - Arbitrary File Read via unparsed-text()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io application allows users to specify XPath expressions as content filters via the include_filters field. These XPath expressions are processed using the elementpath library which implements XPath 3.0/3.1 specification. XPath 3.0 includes the unparsed-text() function which can read arbitrary files from the filesystem. The application does not validate or sanitize XPath expressions to block dangerous functions, allowing an attacker to read any file accessible to the application process. This issue has been patched in version 0.54.4.

CWE CWE-94
Vendor dgtlmoon
Product changedetection.io
Published Mar 6, 2026
Last Updated Mar 9, 2026
Stay Ahead of the Next One

Get instant alerts for dgtlmoon changedetection.io

Be the first to know when new unknown vulnerabilities affecting dgtlmoon changedetection.io are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

dgtlmoon / changedetection.io
< 0.54.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-6fmw-82m7-jq6p github.com: https://github.com/dgtlmoon/changedetection.io/commit/417d57e5749441e4be9acc4010369bded805d66f github.com: https://github.com/dgtlmoon/changedetection.io/releases/tag/0.54.4