{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/@tryghost/activitypub--3.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-53950"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@tryghost/activitypub (\u003c 3.1.0)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","activitypub"],"_cs_type":"advisory","_cs_vendors":["Ghost"],"content_html":"\u003cp\u003eA high-severity cross-site scripting (XSS) vulnerability, tracked as CVE-2026-53950, affects the @tryghost/activitypub package used by the Ghost platform. The vulnerability arises from improper sanitization of content ingested from remote ActivityPub servers. By configuring a malicious ActivityPub server, an attacker can craft posts containing arbitrary JavaScript payloads. When these posts are fetched and rendered by the Ghost ActivityPub client, the payload executes in the context of the user's session. This vulnerability impacts all versions of @tryghost/activitypub prior to 3.1.0. Defenders should note that Ghost instances automatically fetch the patched version (v3.1.0) upon release, but administrators should verify the version status of their local deployments to ensure the update has been applied.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized script execution in the context of the user viewing the malicious post. This can lead to session hijacking, unauthorized actions performed on behalf of the user, or the exfiltration of sensitive information accessible through the browser session. All Ghost deployments utilizing the affected @tryghost/activitypub package are vulnerable if not updated to version 3.1.0 or later.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the @tryghost/activitypub package to version 3.1.0 or later immediately to incorporate the sanitization fix for CVE-2026-53950.\u003c/li\u003e\n\u003cli\u003eReview web server and application logs for suspicious inbound ActivityPub traffic if there is evidence of targeting.\u003c/li\u003e\n\u003cli\u003eAudit the Ghost installation directory to confirm the current version of the @tryghost/activitypub dependency.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T02:00:53Z","date_published":"2026-08-05T02:00:53Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ghost-xss/","summary":"An XSS vulnerability in the @tryghost/activitypub package (CVE-2026-53950) allows attackers to inject arbitrary JavaScript via malicious ActivityPub server posts.","title":"Cross-Site Scripting Vulnerability in Ghost ActivityPub Client","url":"https://feed.craftedsignal.io/briefs/2026-08-ghost-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - @Tryghost/Activitypub (\u003c 3.1.0)","version":"https://jsonfeed.org/version/1.1"}