HIGH 7.5 GitHub
CVE-2026-53950
XSS in Ghost's ActivityPub client
### Impact
The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server.
### Vulnerable Versions
This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected.
### Patches
@tryghost/activitypub v3.1.0 contains a fix for this issue and is also automatically fetched by Ghost.
### References
Ghost thanks Brad Geesaman, Ghost Security for disclosing this vulnerabil
Affected Products
- npm/@tryghost/activitypub < 3.1.0
References
- https://github.com/advisories/GHSA-xpp7-93x6-v29m
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-xpp7-93x6-v29m
- https://nvd.nist.gov/vuln/detail/CVE-2026-53950
- https://github.com/advisories/GHSA-xpp7-93x6-v29m
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-08-04 via GitHub. Affected: npm/@tryghost/activitypub < 3.1.0.
vulnfeed aggregates 9182 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.