### Impact The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. ### Vulnerable Versions This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected. ### Patches @tryghost/activitypub v3.1.0 contains a fix for this issue and is also automatically fetched by Ghost. ### References Ghost thanks Brad Geesaman, Ghost Security for disclosing this vulnerability responsibly. ### For more information If you have any questions or comments about this advisory, email Ghost at [security@ghost.org](mailto:security@ghost.org).
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free