# changedetection.io 0.54.8 - Product: changedetection.io (https://whatsnew.fyi/product/changedetection-io) - Vendor: changedetection.io - Date: 2026-04-04 - Version: 0.54.8 - Original notes: https://github.com/dgtlmoon/changedetection.io/releases/tag/0.54.8 - Permalink: https://whatsnew.fyi/product/changedetection-io/releases/0.54.8 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Fix authentication bypass vulnerability via decorator ordering (CVE-2026-35490) - **added** — Extendable theme pluggy implementation - **changed** — Update openapi-core requirement from ~=0.22 to ~=0.23 ##### What's Changed CVE-2026-35490 - Authentication Bypass via Decorator Ordering * Extendable theme pluggy implementation by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4011 * CI - Ensure all unit tests are run by @dgtlmoon in https://github.com/dgtlmoon/changedetection.io/pull/4022 * Update openapi-core requirement from ~=0.22 to ~=0.23 by @dependabot[bot] in https://github.com/dgtlmoon/changedetection.io/pull/4009 **Full Changelog**: https://github.com/dgtlmoon/changedetection.io/compare/0.54.7...0.54.8