0.55.6

dgtlmoon/changedetection.io0.55.6May 25, 2026by dgtlmoon

AI Summary

A critical security update addressing an SSRF vulnerability alongside UI and LLM improvements.

Key Highlights

  • Fixed SSRF vulnerability in urlparse/urllib3 Parser Differential
  • Added LLM_FEATURES_DISABLED flag to globally disable LLM features
  • Added missing raw_diff token to notifications
  • Refactored LLM settings to use Pydantic
  • Adopted strict mode in linting

New Features

  • Global LLM disable flag
  • LLM settings Pydantic refactor

Full Release Notes

## Security updates
Security - SSRF in ChangeDetection.io via urlparse/urllib3 Parser Differential

## What's Changed
* UI - Preview problem fix for extract_text/ignore_text #4138 by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4169
* UI - LLM - Flag `LLM_FEATURES_DISABLED` to disable all LLM from the UI/system by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4171
* Notifications - `raw_diff` token was missing by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4177
* LLM UI - Blueprint/code also disabled when env flag `LLM_FEATURES_DISABLED` is enabled by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4180
* Llm settings pydantic refactor by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4181
* lint: Bump dennis — adopt `--strict` mode and drop false-positive workarounds by @skkzsh in https://github.com/dgtlmoon/changedetection.io/pull/4182


**Full Changelog**: https://github.com/dgtlmoon/changedetection.io/compare/0.55.5...0.55.6