It appears the image runs as a non root user at least… You can drop unnecessary capabilities https://oneuptime.com/blog/post/2026-01-16-docker-drop-capabilities/view
You can also add firewall redfrictions to container to only allow it to connect to services you want to limit injection attacks.
This would help, but still could be open to a lot of security problems I’d imagine.




Funny enough there is a layer for discord like stuff adding into https://movim.eu/ which relies on the backed of an XMPP server.