Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation that allows attackers to read arbitrary local files by using unblocked XPath 3.0/3.1 functions such as json-doc() and similar file-access primitives. Attackers can exploit the incomplete blocklist of dangerous XPath functions to access sensitive data from the local filesystem. | |
| Title | ChangeDetection.io < 0.54.7 SafeXPath3Parser Bypass Arbitrary File Read | |
| Weaknesses | CWE-184 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-01T19:06:41.847Z
Reserved: 2026-03-31T20:40:15.617Z
Link: CVE-2026-35000
Updated: 2026-04-01T19:06:37.938Z
Status : Received
Published: 2026-04-01T19:16:33.750
Modified: 2026-04-01T19:16:33.750
Link: CVE-2026-35000
No data.
OpenCVE Enrichment
No data.