CVE-2026-29039: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-29039 is an arbitrary file read vulnerability in changedetection.io caused by unsanitized XPath 3.0 expressions processed via the elementpath library. It affects all versions up to and including 0.54.3 of the changedetection.io pip package. The vulnerability was published on March 4, 2026, and patched in version 0.54.4 released the same day. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory, Security Advisory).

Technical details

The root cause is improper input validation (CWE-94) in the include_filters field, which accepts XPath expressions processed by the elementpath library using XPath3Parser. The ValidateCSSJSONXPATHInput validator in forms.py only checks syntactic validity of XPath expressions — it does not block semantically dangerous XPath 3.0 functions. As a result, the xpath_filter() function in html_tools.py (line 213) passes attacker-controlled expressions directly to elementpath.select() with the full XPath3Parser, enabling use of unparsed-text('file:///etc/passwd'), doc(), environment-variable(), and related functions to read arbitrary files or environment variables from the server filesystem. No authentication or special privileges are required to set a watch filter and trigger exploitation (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an unauthenticated attacker to read any file accessible to the changedetection.io application process, including /etc/passwd, application configuration files, API keys, credentials, and SQLite database files. The file contents are returned as "filtered content" and stored as a snapshot viewable in the UI, enabling straightforward exfiltration. There is no integrity or availability impact, but the confidentiality breach can facilitate further attacks such as credential theft or lateral movement if sensitive secrets are exposed (Security Advisory, GitHub Advisory).

Exploitability

A public proof-of-concept Python script is available, demonstrating automated exploitation by creating a watch, injecting a malicious XPath filter, triggering a recheck, and retrieving file contents from the snapshot (Security Advisory). The EPSS score is approximately 0.015% (6th percentile), indicating low current exploitation probability. No in-the-wild exploitation or threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog. The CVSS v4.0 exploit maturity is rated as Proof-of-Concept (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing changedetection.io instances (default port 5000) using Shodan, Censys, or similar tools. Confirm the version is 0.54.3 or earlier.
  2. Create a watch: Send a POST request (or use the UI) to create a new watch for any valid URL (e.g., https://example.com) on the target instance.
  3. Inject malicious XPath filter: Edit the watch and set the CSS/JSONPath/JQ/XPath Filters field to a payload such as xpath:unparsed-text('file:///etc/passwd'). Other dangerous functions include unparsed-text-lines(), doc(), and environment-variable().
  4. Trigger recheck: Force the watch to recheck (via the UI or API endpoint) so the XPath expression is evaluated by elementpath.select() with XPath3Parser.
  5. Retrieve file contents: View the watch snapshot or preview in the UI — the contents of the targeted file are returned as the "filtered content" and stored as a snapshot, completing the file read (Security Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to the watch edit endpoint containing XPath expressions with unparsed-text, doc, or environment-variable in the include_filters parameter; outbound connections from the changedetection.io process to attacker-controlled infrastructure.
  • Logs: Application logs showing watch filter values containing xpath:unparsed-text(, xpath:doc(, or xpath:environment-variable(; repeated recheck triggers for watches with file URI schemes (file:///) in filter fields.
  • File System: Snapshots stored in the changedetection.io datastore containing contents of system files (e.g., /etc/passwd entries, environment variable dumps, or configuration file contents) rather than expected web page content.
  • Process: The changedetection.io Python process accessing unexpected files outside its normal working directory, observable via auditd or similar file access monitoring tools.

Mitigation and workarounds

Upgrade changedetection.io to version 0.54.4 or later, which introduces a SafeXPath3Parser subclass that removes dangerous XPath 3.0 functions (unparsed-text, unparsed-text-lines, unparsed-text-available, doc, doc-available, environment-variable, available-environment-variables) from the parser's symbol table, and applies this safe parser in both html_tools.py and forms.py validation (Release 0.54.4, Patch Commit). Until patching is complete, restrict network access to changedetection.io instances and limit which users can create or edit watches. The blocked function list can also be customized post-patch via the XPATH_BLOCKED_FUNCTIONS environment variable.

Community reactions

The vulnerability was discovered and reported by researchers DhiyaneshGeek and neo-ai-engineer, credited in the GitHub Security Advisory. The fix was published by the maintainer (dgtlmoon) on the same day as disclosure (March 4, 2026), alongside patches for two other CVEs (CVE-2026-29038 and CVE-2026-29065) in the same release (Release 0.54.4). The vulnerability was noted on Bluesky and tracked by multiple vulnerability aggregators shortly after disclosure, reflecting moderate community interest given the public PoC availability.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management