VYPR

@tryghost/activitypub

by Tryghost

CVEs (1)

  • CVE-2026-53950HigJun 24, 2026
    risk 0.42cvss 7.5epss 0.00

    @tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. This vulnerability is fixed in 3.1.0.