PT-2026-29588 · Unknown · Changedetection.Io

CVE-2026-35000

·

Published

2026-04-01

·

Updated

2026-04-02

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ChangeDetection.io versions prior to 0.54.7
Description ChangeDetection.io contains a protection bypass in the SafeXPath3Parser implementation. This allows attackers to read arbitrary local files by using unblocked XPath 3.0/3.1 functions like json-doc() and similar file-access primitives. The incomplete blocklist of dangerous XPath functions enables access to sensitive data on the local filesystem.
Recommendations Update to version 0.54.7 or later.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35000
PYSEC-2026-2131

Affected Products

Changedetection.Io