CVE-2026-29039 | dgtlmoon changedetection.io up to 0.54.3 XPath Expression unparsed-text include_filters code injection (GHSA-6fmw-82m7-jq6p)
A vulnerability has been found in dgtlmoon changedetection.io up to 0.54.3 and classified as critical. Affected by this vulnerability is the function unparsed-text of the component XPath Expression Handler. The manipulation of the argument include_filters leads to code injection.
This vulnerability is referenced as CVE-2026-29039. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.