Self-hosters left vulnerable to XSS vuln due to second-class Docker support

I just got the fix! I still see the “four days old” but docker pulled the new image.