🚨 Security Update: Hollo 0.6.5 Released

We've released 0.6.5 with a critical fix for CVE-2025-53941, addressing an HTML injection vulnerability in federated posts.

Please immediately to protect your instance from potential phishing and XSS attacks.

How to update:

  • Railway: Go to deployments β†’ click three dots β†’ Redeploy
  • Docker: docker pull ghcr.io/fedify-dev/hollo:latest and restart
  • Manual: git pull origin stable && pnpm install and restart server

🚨 λ³΄μ•ˆ μ—…λ°μ΄νŠΈ: Hollo 0.6.5 릴리슀

CVE-2025-53941 취약점을 ν•΄κ²°ν•˜λŠ” 0.6.5λ₯Ό λ¦΄λ¦¬μŠ€ν–ˆμŠ΅λ‹ˆλ‹€. μ—°ν•© κ²Œμ‹œλ¬Όμ˜ HTML μ£Όμž… 취약점이 μˆ˜μ •λ˜μ—ˆμŠ΅λ‹ˆλ‹€.

ν”Όμ‹± 및 XSS κ³΅κ²©μœΌλ‘œλΆ€ν„° μΈμŠ€ν„΄μŠ€λ₯Ό λ³΄ν˜Έν•˜κΈ° μœ„ν•΄ μ¦‰μ‹œ μ—…λ°μ΄νŠΈν•΄ μ£Όμ„Έμš”.

μ—…λ°μ΄νŠΈ 방법:

  • Railway: 배포 νƒ­ β†’ 점 μ„Έ 개 클릭 β†’ Redeploy
  • Docker: docker pull ghcr.io/fedify-dev/hollo:latest ν›„ μž¬μ‹œμž‘
  • μˆ˜λ™: git pull origin stable && pnpm install ν›„ μ„œλ²„ μž¬μ‹œμž‘

2

If you have a fediverse account, you can quote this note from your own instance. Search https://hollo.social/@hollo/01981631-7d3b-7f25-8e0b-98eda768052c on your instance and quote it. (Note that quoting is not supported in Mastodon.)