CVE-2026-53950
Impact
The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server.
Vulnerable Versions
This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected.
Patches
@tryghost/activitypub v3.1.0 contains a fix for this issue and is also automatically fetched by Ghost.
References
Ghost thanks Brad Geesaman, Ghost Security for disclosing this vulnerability responsibly.
For more information
If you have any questions or comments about this advisory, email Ghost at security@ghost.org.
⚡ Watch CVE-2026-53950
Get an email if CVE-2026-53950 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
Advisory coverage (1)
- highGHSA-xpp7-93x6-v29m: XSS in Ghost's ActivityPub clientghsa · 2026-08-04
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-53950)