Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xpp7-93x6-v29m

Опубликовано: 04 авг. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

XSS in Ghost's ActivityPub client

Impact

The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server.

Vulnerable Versions

This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected.

Patches

@tryghost/activitypub v3.1.0 contains a fix for this issue and is also automatically fetched by Ghost.

References

Ghost thanks Brad Geesaman, Ghost Security for disclosing this vulnerability responsibly.

For more information

If you have any questions or comments about this advisory, email Ghost at security@ghost.org.

Пакеты

Наименование

@tryghost/activitypub

npm
Затронутые версииВерсия исправления

< 3.1.0

3.1.0

EPSS

Процентиль: 11%
0.00204
Низкий

7.5 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

@tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. This vulnerability is fixed in 3.1.0.

EPSS

Процентиль: 11%
0.00204
Низкий

7.5 High

CVSS3

Дефекты

CWE-79