THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xpp7-93x6-v29m (high) — XSS in Ghost's ActivityPub client

[GHSA] GHSA-xpp7-93x6-v29m (high) — XSS in Ghost's ActivityPub client

medgithub_advisoriesPublished 2026-08-04

GHSA-xpp7-93x6-v29m Severity: high CVE: CVE-2026-53950

XSS in Ghost's ActivityPub client

### Impact

The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server.

### Vulnerable Versions

This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected.

### Patches

@t

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xpp7-93x6-v29m