Executive brief
changedetection.io is an open-source application that monitors websites for changes and backs up configuration data. A path traversal vulnerability in the backup restore functionality allows attackers to upload a specially crafted ZIP file that extracts files outside the intended directory, potentially overwriting sensitive application settings, disabling authentication, or injecting malicious watch configurations. An attacker with access to the restore feature can completely compromise the application without needing elevated privileges.
Technical details
The vulnerability is a Zip Slip path traversal flaw (CWE-22) in the backup restore functionality. The application uses Python's `zipfile.extractall()` without validating entry paths, allowing ZIP archives containing `../` sequences to escape the intended extraction directory. An attacker can craft a malicious ZIP file with entries like `../secret.txt` or `../changedetection.json` that, when extracted, overwrite critical application files. No authentication is required to exploit this vulnerability—attackers need only network access to the `/backups/restore` endpoint. Successful exploitation enables disabling application passwords, injecting backdoor watches, or forging authentication sessions. The vulnerability is fixed in version 0.54.4; all versions through 0.54.3 are affected.
Affected products
- changedetection.io changedetection.io < 0.54.4
Timeline
- 2026-03-04: disclosed
- 2026-03-04: patched: Fixed in version 0.54.4