๐Ÿšจ Security Update: Hollo 0.6.5 Released

We've released 0.6.5 with a critical fix for CVE-2025-53941, addressing an HTML injection vulnerability in federated posts.

Please immediately to protect your instance from potential phishing and XSS attacks.

How to update:

  • Railway: Go to deployments โ†’ click three dots โ†’ Redeploy
  • Docker: docker pull ghcr.io/fedify-dev/hollo:latest and restart
  • Manual: git pull origin stable && pnpm install and restart server
0

If you have a fediverse account, you can quote this note from your own instance. Search https://hollo.social/@hollo/01981630-ae67-7005-a7bd-4ab04e215cf0 on your instance and quote it. (Note that quoting is not supported in Mastodon.)