CVE-2026-53950highCWE-79

CVE-2026-53950: high-severity vulnerability in TryGhost Ghost

@tryghost/activitypub: XSS in Ghost's ActivityPub client

Published

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 0.4%
exploitation probability
0.4%top 73% of all CVEs
observed exploitation
nono source reports it
@tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. This vulnerability is fixed in 3.1.0.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
TryGhost · Ghost