CVE-2026-53950
TryGhost Ghost 취약점
@tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. This vulnerability is fixed in 3.1.0.
- 대응 우선순위
- 점검
- CVSS
- 7.5
- EPSS
- 0.20% 백분위 10.7% · 2026.07.28 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.25