diff --git a/Changelog.md b/Changelog.md
index b360d79b8b7badbfe8588e23236ea0c1300a805f..e326667349c66d6f20662c9055ba8aa61ec3360b 100644
--- a/Changelog.md
+++ b/Changelog.md
@@ -1,3 +1,7 @@
+# 0.6.4.1
+
+Fixes a possible Remote Code Execution ([CVE-2016-4658](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4658)) and a possible DoS ([CVE-2016-5131](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5131)) by updating Nokogiri, which in turn updates libxml2.
+
 # 0.6.4.0
 
 ## Refactor
diff --git a/Gemfile b/Gemfile
index aa5951a1f5a7970a5c79bb3b389fe14a281681b5..6db6ec2c8c4e2d188c1ffe88421ac3fdeeb68d7e 100644
--- a/Gemfile
+++ b/Gemfile
@@ -132,7 +132,7 @@ gem "leaflet-rails",       "0.7.7"
 
 # Parsing
 
-gem "nokogiri",          "1.7.0.1"
+gem "nokogiri",          "1.7.1"
 gem "open_graph_reader", "0.6.2" # also update User-Agent in features/support/webmock.rb
 gem "redcarpet",         "3.4.0"
 gem "ruby-oembed",       "0.10.1"
diff --git a/Gemfile.lock b/Gemfile.lock
index 562226990878184a1aee8679273612216c7c2ebc..880e2415faee58adb66f1238310056010d57105f 100644
--- a/Gemfile.lock
+++ b/Gemfile.lock
@@ -395,7 +395,7 @@ GEM
     nenv (0.3.0)
     nested_form (0.3.2)
     nio4r (2.0.0)
-    nokogiri (1.7.0.1)
+    nokogiri (1.7.1)
       mini_portile2 (~> 2.1.0)
     notiffany (0.1.1)
       nenv (~> 0.1)
@@ -845,7 +845,7 @@ DEPENDENCIES
   minitest
   mobile-fu (= 1.3.1)
   mysql2 (= 0.4.5)
-  nokogiri (= 1.7.0.1)
+  nokogiri (= 1.7.1)
   omniauth (= 1.4.2)
   omniauth-facebook (= 4.0.0)
   omniauth-tumblr (= 1.2)
diff --git a/config/defaults.yml b/config/defaults.yml
index 8a58394a17d339bdd5ad6dfa1065805942609f03..5c29c1166d155e2a008e05695712d574ae8327ce 100644
--- a/config/defaults.yml
+++ b/config/defaults.yml
@@ -4,7 +4,7 @@
 
 defaults:
   version:
-    number: "0.6.4.0" # Do not touch unless doing a release, do not backport the version number that's in master
+    number: "0.6.4.1" # Do not touch unless doing a release, do not backport the version number that's in master
   heroku: false
   environment:
     url: "http://localhost:3000/"