A AegiFlow
HIGHCVSS 7.5EPSS 0.2%

CVE-2026-53950

XSS in Ghost's ActivityPub client

Published
2026-08-04
Modified
2026-08-04
EPSS percentile
11%
Aliases
GHSA-xpp7-93x6-v29m
Sources
github-advisory

Summary

### Impact The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. ### Vulnerable Versions This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected. ### Patches @tryghost/activitypub v3.1.0 contains a fix for this issue and is also automatically fetched by Ghost. ### References Ghost thanks Brad Geesaman, Ghost Security for disclosing this vulnerability responsibly. ### For more information If you have any questions or comments about this advisory, email Ghost at [[email protected]](mailto:[email protected]).

Affected packages

EcosystemPackageAffected versionsFixed versions
npm@tryghost/activitypub3.1.0

Remediation: Upgrade to 3.1.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.