esmBot 2024.6.0 has been released to fix some issues.

Among these issues is a security vulnerability that can allow attackers to access images served in private loopback/local networks. Self-hosters are recommended to update immediately. (Thank you to @pandaninjas for finding and reporting this!)

Full release notes are available here: https://github.com/esmBot/esmBot/releases/tag/v2024.6.0

Release 2024.6.0 · esmBot/esmBot

This release fixes some issues, including a security issue. Self-hosters are recommended to update immediately. Changes Fixed an issue where images could be accessed from the bot's local network (...

GitHub