HIGH 7.5 GitHub

CVE-2026-53950

XSS in Ghost's ActivityPub client

### Impact The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. ### Vulnerable Versions This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected. ### Patches @tryghost/activitypub v3.1.0 contains a fix for this issue and is also automatically fetched by Ghost. ### References Ghost thanks Brad Geesaman, Ghost Security for disclosing this vulnerabil

Affected Products

References

Published: 2026-08-04 · Source: GitHub · Feed updated: 2026-08-05
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-08-04 via GitHub. Affected: npm/@tryghost/activitypub < 3.1.0.
vulnfeed aggregates 9182 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.