diff --git a/Changelog.md b/Changelog.md
index 879ca4e86b589ab77f15a9e236b7213bf7f6eea6..c552f0b4f7e74d0e1582c57c518ab65c6cd78d39 100644
--- a/Changelog.md
+++ b/Changelog.md
@@ -1,3 +1,7 @@
+# 0.7.0.1
+
+Update nokogiri to fix [multiple libxml2 vulnerabilities](https://usn.ubuntu.com/usn/usn-3424-1/).
+
 # 0.7.0.0
 
 ## Supported Ruby versions
diff --git a/Gemfile b/Gemfile
index 532d4dd9e1548d410ff11bea906a74c58ac85ca4..c7cc848d9dbf071018fb983f67d3d36417281747 100644
--- a/Gemfile
+++ b/Gemfile
@@ -135,7 +135,7 @@ gem "leaflet-rails",       "1.1.0"
 
 # Parsing
 
-gem "nokogiri",          "1.8.0"
+gem "nokogiri",          "1.8.1"
 gem "open_graph_reader", "0.6.2" # also update User-Agent in features/support/webmock.rb
 gem "redcarpet",         "3.4.0"
 gem "ruby-oembed",       "0.12.0"
diff --git a/Gemfile.lock b/Gemfile.lock
index 5bc4f2ec5c80f46fe9e96fd3071b7b1cca4644b3..b2365e6224829a495b054f3975dd1c4764177b86 100644
--- a/Gemfile.lock
+++ b/Gemfile.lock
@@ -374,7 +374,7 @@ GEM
     mime-types-data (3.2016.0521)
     mini_magick (4.8.0)
     mini_mime (0.1.4)
-    mini_portile2 (2.2.0)
+    mini_portile2 (2.3.0)
     minitest (5.10.3)
     mobile_fu (1.4.0)
       rack-mobile-detect
@@ -387,8 +387,8 @@ GEM
     naught (1.1.0)
     nenv (0.3.0)
     nio4r (2.1.0)
-    nokogiri (1.8.0)
-      mini_portile2 (~> 2.2.0)
+    nokogiri (1.8.1)
+      mini_portile2 (~> 2.3.0)
     notiffany (0.1.1)
       nenv (~> 0.1)
       shellany (~> 0.0)
@@ -820,7 +820,7 @@ DEPENDENCIES
   minitest
   mobile_fu (= 1.4.0)
   mysql2 (= 0.4.9)
-  nokogiri (= 1.8.0)
+  nokogiri (= 1.8.1)
   omniauth (= 1.6.1)
   omniauth-facebook (= 4.0.0)
   omniauth-tumblr (= 1.2)
@@ -904,4 +904,4 @@ DEPENDENCIES
   will_paginate (= 3.1.6)
 
 BUNDLED WITH
-   1.15.3
+   1.15.4
diff --git a/config/defaults.yml b/config/defaults.yml
index 2ffaf3fe06185f6335c5e254ef04ed5b73e8891c..2871abf7b7d18ceec85530d57a8b7e7dc0041759 100644
--- a/config/defaults.yml
+++ b/config/defaults.yml
@@ -4,7 +4,7 @@
 
 defaults:
   version:
-    number: "0.7.0.0" # Do not touch unless doing a release, do not backport the version number that's in master
+    number: "0.7.0.1" # Do not touch unless doing a release, do not backport the version number that's in master
   heroku: false
   environment:
     url: "http://localhost:3000/"