CVE-2026-29065
changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore functionality allows arbitrary file overwrite via path traversal in uploaded ZIP archives. This issue has been patched in version 0.54.4.
- Affected products
- Flask, Changedetection.Io, Zipfile
- Webtechnologies Changedetection
- < 0.54.4
- Fix
- Available
- CVSS 4.0
- 9.3 CRITICAL
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 0.5% (43th percentile)
- Weakness
- CWE-22
- NVD status
- Analyzed
- Published
- 2026-03-06
CVE-2026-29065 at NVD
No indexed exploits for CVE-2026-29065 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-29065 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.