CVE-2026-33981: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-33981 is an environment variable disclosure vulnerability in changedetection.io that allows attackers to exfiltrate all server process environment variables — including password hashes, API keys, and infrastructure credentials — via the jq env builtin in include filter expressions. It affects all versions of changedetection.io up to and including 0.54.6 (pip package). The vulnerability was published on March 26, 2026, and patched in version 0.54.7 released the same day. It carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 8.3 (High) (Github Advisory, Security Advisory).

Technical details

The root cause is CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). In changedetectionio/html_tools.py (lines 380–388), user-supplied jq: and jqraw: filter expressions are compiled and executed via the Python jq module without any restriction on dangerous builtins. The form validator in forms.py only checks that the expression compiles successfully — it does not block hazardous functions like env or $ENV. Because the jq env builtin reads all process environment variables regardless of the input JSON data, an attacker can supply jqraw:env as an include filter to dump every environment variable from the server process into the watch snapshot, which is then visible in the web UI and included in notification messages (Security Advisory, Patch Commit).

Impact

Successful exploitation results in full disclosure of all server process environment variables, including SALTED_PASS (the password hash used for authentication, enabling offline cracking or session forgery), PLAYWRIGHT_DRIVER_URL, WEBDRIVER_URL, HTTP_PROXY/HTTPS_PROXY credentials, database connection strings, and any API keys or tokens injected as environment variables. Leaked proxy or browser automation credentials can be used to pivot into other internal systems, making this a high-impact credential theft and lateral movement enabler. There is no integrity or availability impact, but the confidentiality impact extends to both the vulnerable system and subsequent systems reachable via exposed credentials (Security Advisory, Github Advisory).

Exploitability

A complete proof-of-concept exploit consisting of three curl commands is publicly available in the official security advisory, making this trivially exploitable (Security Advisory). The vulnerability requires only low privileges (or no authentication in the default configuration, since changedetection.io ships with no password and no API key requirement), and exploitation is fully network-accessible with low complexity. The EPSS score is approximately 0.016–0.018%, and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (Github Advisory). No specific threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible changedetection.io instances running version 0.54.6 or earlier. Default deployments have no password and no API key, so no credentials are needed.
  2. Create a malicious watch: Send a POST request to the /api/v1/watch API endpoint with jqraw:env as the include filter, pointing to any JSON URL (e.g., https://httpbin.org/json):
curl -X POST http://target:5000/api/v1/watch \
  -H "Content-Type: application/json" \
  -H "x-api-key: " \
  -d '{"url": "https://httpbin.org/json", "include_filters": ["jqraw:env"], "time_between_check": {"seconds": 30}}'
  1. Trigger a recheck: Force the watch to execute immediately by calling the recheck endpoint:
curl "http://target:5000/api/v1/watch/<watch-uuid>?recheck=true" -H "x-api-key: "
  1. Retrieve exfiltrated data: View the watch's latest snapshot in the web UI or via the API. The snapshot will contain all server process environment variables, including SALTED_PASS, PLAYWRIGHT_DRIVER_URL, HTTP_PROXY, and all other secrets.
  2. Leverage stolen credentials: Use the extracted SALTED_PASS hash for offline cracking or session forgery; use proxy/browser automation URLs to pivot into internal infrastructure (Security Advisory).

Indicators of compromise

  • Network: Unexpected POST requests to /api/v1/watch from unknown or external IP addresses, especially with no x-api-key header; GET requests to /api/v1/watch/<uuid>?recheck=true shortly after watch creation.
  • Logs: Application logs showing watch creation with include_filters containing jqraw:env or jq:env; access log entries for /api/v1/watch from unusual sources.
  • File System: Watch snapshot files on disk (typically in the changedetection.io data directory) containing environment variable dictionaries with keys such as SALTED_PASS, PLAYWRIGHT_DRIVER_URL, HTTP_PROXY, WERKZEUG_SERVER_FD, HOME, PATH, SHELL.
  • Application Behavior: Notification messages (email, webhook, etc.) sent by changedetection.io containing environment variable dumps if notifications are configured for the malicious watch (Security Advisory).

Mitigation and workarounds

Upgrade changedetection.io to version 0.54.7 or later, which introduces a validate_jq_expression() function that blocks dangerous jq builtins including env, $ENV, include, import, input/inputs, debug, stderr, halt, $__loc__, builtins, and modulemeta (Release 0.54.7, Patch Commit). If immediate upgrade is not possible: (1) restrict network access to changedetection.io to trusted internal networks only; (2) enable password authentication and API key requirements; (3) rotate all credentials exposed as environment variables (passwords, API keys, proxy credentials, database connection strings). After patching, audit watch snapshots and notification logs for any evidence of prior exploitation and invalidate any potentially exposed credentials (Github Advisory).

Community reactions

The vulnerability was credited to reporters sajdakabir and zerotrail-ai in the official advisory. Social media activity was observed on Bluesky shortly after disclosure. Coverage appeared across vulnerability tracking platforms including VulDB, CVEFeed, and radar.offseq.com within hours of publication. No major vendor statements beyond the maintainer's own advisory and patch have been identified (Security Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management