Feed/CVE-2026-53950
CVE-2026-53950HIGHCVSS 7.5

XSS in Ghost's ActivityPub client

Published Aug 4, 2026·Updated Aug 4, 2026

NVD Description

### Impact The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. ### Vulnerable Versions This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected. ### Patches @tryghost/activitypub v3.1.0 contains a fix for this issue and is also automatically fetched by Ghost. ### References Ghost thanks Brad Geesaman, Ghost Security for disclosing this vulnerability responsibly. ### For more information If you have any questions or comments about this advisory, email Ghost at [security@ghost.org](mailto:security@ghost.org).

Affected Packages (1)

@tryghost/activitypubNPM
Fixed in 3.1.0

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free