CVE-2026-29038

changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, there is a reflected cross-site scripting (XSS) vulnerability identified in the /rss/tag/ endpoint of changedetection.io. The tag_uuid path parameter is reflected directly in the HTTP response body without HTML escaping. Since Flask returns text/html by default for plain string responses, the browser parses and executes injected JavaScript. This issue has been patched in version 0.54.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:webtechnologies:changedetection:*:*:*:*:*:*:*:*

History

10 Mar 2026, 19:38

Type Values Removed Values Added
Summary
  • (es) changedetection.io es una herramienta gratuita de código abierto para la detección de cambios en páginas web. Antes de la versión 0.54.4, existe una vulnerabilidad de cross-site scripting (XSS) reflejado identificada en el endpoint /rss/tag/ de changedetection.io. El parámetro de ruta tag_uuid se refleja directamente en el cuerpo de la respuesta HTTP sin escape HTML. Dado que Flask devuelve text/html por defecto para respuestas de cadena de texto plano, el navegador analiza y ejecuta JavaScript inyectado. Este problema ha sido parcheado en la versión 0.54.4.
First Time Webtechnologies changedetection
Webtechnologies
CPE cpe:2.3:a:webtechnologies:changedetection:*:*:*:*:*:*:*:*
References () https://github.com/dgtlmoon/changedetection.io/commit/ec7d56f85d1e9690fca7cb4711c1fb20dffec780 - () https://github.com/dgtlmoon/changedetection.io/commit/ec7d56f85d1e9690fca7cb4711c1fb20dffec780 - Patch
References () https://github.com/dgtlmoon/changedetection.io/releases/tag/0.54.4 - () https://github.com/dgtlmoon/changedetection.io/releases/tag/0.54.4 - Product, Release Notes
References () https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-8whx-v8qq-pq64 - () https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-8whx-v8qq-pq64 - Exploit, Mitigation, Vendor Advisory

06 Mar 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-06 07:16

Updated : 2026-03-10 19:38


NVD link : CVE-2026-29038

Mitre link : CVE-2026-29038

CVE.ORG link : CVE-2026-29038


JSON object : View

Products Affected

webtechnologies

  • changedetection
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')