XML Parsing Vulnerability in Changedetection.io Web Page Monitoring Tool
CVE-2026-41895
8.2HIGH
What is CVE-2026-41895?
Changedetection.io, a popular open-source web page change detection tool, is vulnerable due to improper handling of XML input. In versions prior to 0.54.9, the xpath_filter() function switches to XML mode without disabling critical security features such as external entity resolution and DTD loading. This vulnerability allows attackers to exploit the system by sending untrusted XML bytes to the parser, potentially leading to unauthorized access and data exposure. For more detailed information, refer to the security advisory.
Affected Version(s)
changedetection.io <= 0.54.9
