Web Page Change Detection Tool Vulnerability in Changedetection.io
CVE-2026-33981

8.3HIGH

Key Information:

Vendor

Dgtlmoon

Vendor
CVE Published:
27 March 2026

What is CVE-2026-33981?

Changedetection.io, an open-source web page change detection tool, contains a vulnerability where the jq: and jqraw: filter expressions allow the use of the jq env builtin. This feature can be exploited by both authenticated users and unauthenticated users (if no password is configured) to leak sensitive environment variables stored in the watch snapshot. Variables such as SALTED_PASS, PLAYWRIGHT_DRIVER_URL, and HTTP_PROXY may be compromised. This issue is addressed in version 0.54.7, which patches the vulnerability.

Affected Version(s)

changedetection.io < 0.54.7

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.