CVE-2026-53950
TryGhost Ghost
@tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. This vulnerability is fixed in 3.1.0.
- CVSS
- 7.5
- EPSS
- 0.20% 10.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.25