Executive brief
changedetection.io is a tool used to monitor websites for content changes. A security vulnerability exists where the tool incorrectly processes XML data from monitored sites. An attacker who controls a monitored website could use this flaw to read sensitive files from the server running the software, potentially leading to data theft or exposure of system configurations.
Technical details
An XML External Entity (XXE) vulnerability exists in the `xpath_filter()` function within `changedetectionio/html_tools.py`. The application uses `lxml.etree.XMLParser` to parse XML/RSS content but fails to explicitly disable external entity resolution (`resolve_entities=False`), DTD loading, or network lookups. An attacker who controls the XML content of a monitored URL can trigger this vulnerability by using an XPath include filter. This allows the attacker to disclose sensitive local files from the host system, which are then included in the watch output, diff history, or notification channels. The vulnerability is present in versions up to and including 0.54.9.
Affected products
- dgtlmoon changedetection.io <= 0.54.9
Timeline
- 2026-04-27: disclosed: Initial disclosure to vendor
- 2026-05-04: advisory: GitHub Advisory published
- 2026-05-12: other: NVD publication date