CVE-2026-35000 is a protection bypass vulnerability affecting ChangeDetection.io versions prior to 0.54.7, specifically within its SafeXPath3Parser implementation. This flaw allows attackers to read arbitrary local files by leveraging unblocked XPath 3.0/3.1 functions such as json-doc() and similar file-access primitives. Rated Medium (CVSS 6.5), the vulnerability has a remote attack vector with low complexity and privileges, leading to a high confidentiality impact by enabling access to sensitive local filesystem data. There is currently no evidence of active exploitation, public exploit code availability, or significant community discussion regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.54.7CPE matchmatch criteria | cpe:2.3:a:webtechnologies:changedetection:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.