GHSA-8757-69j2-hx56 · Severity: high · Ecosystem: pip — changedetection.io has an Arbitrary Local File Read via a crafted backup restore
changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by trusting attacker-controlled snapshot paths restored from backup files. The vulnerable flow starts in the backup restore logic. When a backup ZIP is restored, the application extracts the archive and copies each restored watch UUID directory directly into the live datastore using shutil.copytree(entry.path, dst_dir). This preserves attacker-controlled files inside the restored watch directory, including history.txt. After restore, the application parses history.txt in the watch history property and returns the contents of the targeted local file. This vulnerability is fixed in 0.55.1.
Conclusion & alert: CVE-2026-43891 is rated Exploit Available (50/100): CVSS High severity, with low exploitation likelihood (EPSS 0.03%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-13 | — | 0.03% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-8757-69j2-hx56 · Severity: high · Ecosystem: pip — changedetection.io has an Arbitrary Local File Read via a crafted backup restore
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| webtechnologies | changedetection | < 0.55.1 | cpe:2.3:a:webtechnologies:changedetection:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-8757-69j2-hx56 | Exploit Mitigation Vendor Advisory |
| https://github.com/pocket-id/pocket-id/security/advisories/GHSA-w6p7-2fxx-4f44 | Exploit Mitigation Vendor Advisory Not Applicable |