CVE-2026-33981
changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include filter expressions allow use of the jq `env` builtin, which reads all process environment variables and stores them as the watch snapshot. An authenticated user (or unauthenticated user when no password is set, the default) can leak sensitive environment variables including `SALTED_PASS`, `PLAYWRIGHT_DRIVER_URL`, `HTTP_PROXY`, and any secrets passed as env vars to the container. Version 0.54.7 patches the issue.
- Affected products
- Playright, Changedetection.Io, Jq
- Webtechnologies Changedetection
- < 0.54.7
- Fix
- Available
- CVSS 4.0
- 8.3 HIGH
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.5% (39th percentile)
- Weakness
- CWE-200
- NVD status
- Analyzed
- Published
- 2026-03-27
No indexed exploits for CVE-2026-33981 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-33981 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.