Web Page Change Detection Tool Vulnerability in Changedetection.io
CVE-2026-33981
8.3HIGH
What is CVE-2026-33981?
Changedetection.io, an open-source web page change detection tool, contains a vulnerability where the jq: and jqraw: filter expressions allow the use of the jq env builtin. This feature can be exploited by both authenticated users and unauthenticated users (if no password is configured) to leak sensitive environment variables stored in the watch snapshot. Variables such as SALTED_PASS, PLAYWRIGHT_DRIVER_URL, and HTTP_PROXY may be compromised. This issue is addressed in version 0.54.7, which patches the vulnerability.
Affected Version(s)
changedetection.io < 0.54.7
