
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29039 is an arbitrary file read vulnerability in changedetection.io caused by unsanitized XPath 3.0 expressions processed via the elementpath library. It affects all versions up to and including 0.54.3 of the changedetection.io pip package. The vulnerability was published on March 4, 2026, and patched in version 0.54.4 released the same day. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory, Security Advisory).
The root cause is improper input validation (CWE-94) in the include_filters field, which accepts XPath expressions processed by the elementpath library using XPath3Parser. The ValidateCSSJSONXPATHInput validator in forms.py only checks syntactic validity of XPath expressions — it does not block semantically dangerous XPath 3.0 functions. As a result, the xpath_filter() function in html_tools.py (line 213) passes attacker-controlled expressions directly to elementpath.select() with the full XPath3Parser, enabling use of unparsed-text('file:///etc/passwd'), doc(), environment-variable(), and related functions to read arbitrary files or environment variables from the server filesystem. No authentication or special privileges are required to set a watch filter and trigger exploitation (GitHub Advisory, Patch Commit).
Successful exploitation allows an unauthenticated attacker to read any file accessible to the changedetection.io application process, including /etc/passwd, application configuration files, API keys, credentials, and SQLite database files. The file contents are returned as "filtered content" and stored as a snapshot viewable in the UI, enabling straightforward exfiltration. There is no integrity or availability impact, but the confidentiality breach can facilitate further attacks such as credential theft or lateral movement if sensitive secrets are exposed (Security Advisory, GitHub Advisory).
A public proof-of-concept Python script is available, demonstrating automated exploitation by creating a watch, injecting a malicious XPath filter, triggering a recheck, and retrieving file contents from the snapshot (Security Advisory). The EPSS score is approximately 0.015% (6th percentile), indicating low current exploitation probability. No in-the-wild exploitation or threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog. The CVSS v4.0 exploit maturity is rated as Proof-of-Concept (GitHub Advisory).
https://example.com) on the target instance.CSS/JSONPath/JQ/XPath Filters field to a payload such as xpath:unparsed-text('file:///etc/passwd'). Other dangerous functions include unparsed-text-lines(), doc(), and environment-variable().elementpath.select() with XPath3Parser.unparsed-text, doc, or environment-variable in the include_filters parameter; outbound connections from the changedetection.io process to attacker-controlled infrastructure.xpath:unparsed-text(, xpath:doc(, or xpath:environment-variable(; repeated recheck triggers for watches with file URI schemes (file:///) in filter fields./etc/passwd entries, environment variable dumps, or configuration file contents) rather than expected web page content.auditd or similar file access monitoring tools.Upgrade changedetection.io to version 0.54.4 or later, which introduces a SafeXPath3Parser subclass that removes dangerous XPath 3.0 functions (unparsed-text, unparsed-text-lines, unparsed-text-available, doc, doc-available, environment-variable, available-environment-variables) from the parser's symbol table, and applies this safe parser in both html_tools.py and forms.py validation (Release 0.54.4, Patch Commit). Until patching is complete, restrict network access to changedetection.io instances and limit which users can create or edit watches. The blocked function list can also be customized post-patch via the XPATH_BLOCKED_FUNCTIONS environment variable.
The vulnerability was discovered and reported by researchers DhiyaneshGeek and neo-ai-engineer, credited in the GitHub Security Advisory. The fix was published by the maintainer (dgtlmoon) on the same day as disclosure (March 4, 2026), alongside patches for two other CVEs (CVE-2026-29038 and CVE-2026-29065) in the same release (Release 0.54.4). The vulnerability was noted on Bluesky and tracked by multiple vulnerability aggregators shortly after disclosure, reflecting moderate community interest given the public PoC availability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."