CVE-2026-53950
XSS in Ghost's ActivityPub client
Summary
### Impact The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. ### Vulnerable Versions This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected. ### Patches @tryghost/activitypub v3.1.0 contains a fix for this issue and is also automatically fetched by Ghost. ### References Ghost thanks Brad Geesaman, Ghost Security for disclosing this vulnerability responsibly. ### For more information If you have any questions or comments about this advisory, email Ghost at [[email protected]](mailto:[email protected]).
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| npm | @tryghost/activitypub | — | 3.1.0 |
Remediation: Upgrade to 3.1.0 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.
EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.