
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33981 is an environment variable disclosure vulnerability in changedetection.io that allows attackers to exfiltrate all server process environment variables — including password hashes, API keys, and infrastructure credentials — via the jq env builtin in include filter expressions. It affects all versions of changedetection.io up to and including 0.54.6 (pip package). The vulnerability was published on March 26, 2026, and patched in version 0.54.7 released the same day. It carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 8.3 (High) (Github Advisory, Security Advisory).
The root cause is CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). In changedetectionio/html_tools.py (lines 380–388), user-supplied jq: and jqraw: filter expressions are compiled and executed via the Python jq module without any restriction on dangerous builtins. The form validator in forms.py only checks that the expression compiles successfully — it does not block hazardous functions like env or $ENV. Because the jq env builtin reads all process environment variables regardless of the input JSON data, an attacker can supply jqraw:env as an include filter to dump every environment variable from the server process into the watch snapshot, which is then visible in the web UI and included in notification messages (Security Advisory, Patch Commit).
Successful exploitation results in full disclosure of all server process environment variables, including SALTED_PASS (the password hash used for authentication, enabling offline cracking or session forgery), PLAYWRIGHT_DRIVER_URL, WEBDRIVER_URL, HTTP_PROXY/HTTPS_PROXY credentials, database connection strings, and any API keys or tokens injected as environment variables. Leaked proxy or browser automation credentials can be used to pivot into other internal systems, making this a high-impact credential theft and lateral movement enabler. There is no integrity or availability impact, but the confidentiality impact extends to both the vulnerable system and subsequent systems reachable via exposed credentials (Security Advisory, Github Advisory).
A complete proof-of-concept exploit consisting of three curl commands is publicly available in the official security advisory, making this trivially exploitable (Security Advisory). The vulnerability requires only low privileges (or no authentication in the default configuration, since changedetection.io ships with no password and no API key requirement), and exploitation is fully network-accessible with low complexity. The EPSS score is approximately 0.016–0.018%, and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (Github Advisory). No specific threat actor attribution has been reported.
/api/v1/watch API endpoint with jqraw:env as the include filter, pointing to any JSON URL (e.g., https://httpbin.org/json):curl -X POST http://target:5000/api/v1/watch \
-H "Content-Type: application/json" \
-H "x-api-key: " \
-d '{"url": "https://httpbin.org/json", "include_filters": ["jqraw:env"], "time_between_check": {"seconds": 30}}'curl "http://target:5000/api/v1/watch/<watch-uuid>?recheck=true" -H "x-api-key: "SALTED_PASS, PLAYWRIGHT_DRIVER_URL, HTTP_PROXY, and all other secrets.SALTED_PASS hash for offline cracking or session forgery; use proxy/browser automation URLs to pivot into internal infrastructure (Security Advisory)./api/v1/watch from unknown or external IP addresses, especially with no x-api-key header; GET requests to /api/v1/watch/<uuid>?recheck=true shortly after watch creation.include_filters containing jqraw:env or jq:env; access log entries for /api/v1/watch from unusual sources.SALTED_PASS, PLAYWRIGHT_DRIVER_URL, HTTP_PROXY, WERKZEUG_SERVER_FD, HOME, PATH, SHELL.Upgrade changedetection.io to version 0.54.7 or later, which introduces a validate_jq_expression() function that blocks dangerous jq builtins including env, $ENV, include, import, input/inputs, debug, stderr, halt, $__loc__, builtins, and modulemeta (Release 0.54.7, Patch Commit). If immediate upgrade is not possible: (1) restrict network access to changedetection.io to trusted internal networks only; (2) enable password authentication and API key requirements; (3) rotate all credentials exposed as environment variables (passwords, API keys, proxy credentials, database connection strings). After patching, audit watch snapshots and notification logs for any evidence of prior exploitation and invalidate any potentially exposed credentials (Github Advisory).
The vulnerability was credited to reporters sajdakabir and zerotrail-ai in the official advisory. Social media activity was observed on Bluesky shortly after disclosure. Coverage appeared across vulnerability tracking platforms including VulDB, CVEFeed, and radar.offseq.com within hours of publication. No major vendor statements beyond the maintainer's own advisory and patch have been identified (Security Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."