Pleroma security release: 2.5.4

Pleroma 2.5.4 is a security release. Fixes a file loading vulnerability via XML External Entity (XXE).

Upgrade notes

From source only

  1. Recompile Pleroma:

    MIX_ENV=prod mix compile
    

Everyone

  1. Restart Pleroma

Frontend changes

None.

Backend changes

Security

— lanodan