CVE-2026-53950
published 2026-06-24CVE-2026-53950: @tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts…
PriorityP341high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
0.35%
26.6th percentile
@tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. This vulnerability is fixed in 3.1.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tryghost | activitypub | >= 0 < 3.1.0 | 3.1.0 |
| tryghost | ghost | < 3.1.0 | 3.1.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
XSS in Ghost's ActivityPub client
ghsa·2026-08-04
CVE-2026-53950 [HIGH] CWE-79 XSS in Ghost's ActivityPub client
XSS in Ghost's ActivityPub client
### Impact
The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server.
### Vulnerable Versions
This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected.
### Patches
@tryghost/activitypub v3.1.0 contains a fix for this issue and is also automatically fetched by Ghost.
### References
Ghost thanks Brad Geesaman, Ghost Security for disclosing this vulnerability responsibly.
### For more information
If you have any questions or comments about this advisory, email Ghost at [[email protected]](mailto:[email protected]).
VulDB
TryGhost up to 3.0.x cross site scripting
vuldb·2026-06-24·CVSS 7.5
CVE-2026-53950 [HIGH] TryGhost up to 3.0.x cross site scripting
A vulnerability marked as problematic has been reported in TryGhost Ghost up to 3.0.x. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-53950. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-24
Published