CVE-2026-35000: ChangeDetection.io < 0.54.7 SafeXPath3Parser Bypass Arbitrary File Read
ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation that allows attackers to read arbitrary local files by using unblocked XPath 3.0/3.1 functions such as json-doc() and similar file-access primitives. Attackers can exploit the incomplete blocklist of dangerous XPath functions to access sensitive data from the local filesystem.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ChangeDetection.ioto a version that resolves this vulnerability.Fixed in 0.54.7Patch ChangeDetection.io < 0.54.7 SafeXPath3Parser Bypass Arbitrary File Read
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35000?
CVE-2026-35000 is considered a high severity vulnerability due to its potential to allow arbitrary file read access.
How do I fix CVE-2026-35000?
To fix CVE-2026-35000, upgrade ChangeDetection.io to version 0.54.7 or later.
What systems are affected by CVE-2026-35000?
CVE-2026-35000 affects ChangeDetection.io versions prior to 0.54.7.
Can CVE-2026-35000 allow remote code execution?
CVE-2026-35000 does not directly lead to remote code execution but allows access to local files which can be sensitive.
What should I do if I am unable to upgrade due to compatibility issues with CVE-2026-35000?
If you cannot upgrade, consider implementing additional security controls such as file access restrictions to mitigate the risks associated with CVE-2026-35000.