CVE-2026-33981 affects changedetection.io versions prior to 0.54.7, enabling authenticated users (or unauthenticated if no password is configured) to leak sensitive environment variables. This vulnerability arises from the `jq:` and `jqraw:` include filter expressions' ability to use the jq `env` builtin, which captures all process environment variables, including secrets like `SALTED_PASS` or `HTTP_PROXY`. Rated with a CVSSv4 score of 8.3 HIGH, this flaw (CWE-200) presents a high confidentiality impact with a network attack vector and low attack complexity. Currently, there is no evidence of active exploitation, no public exploit code available, and minimal community discussion, with the vulnerability not appearing on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.54.7CPE matchmatch criteria | cpe:2.3:a:webtechnologies:changedetection:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.