VDB
KO
HIGH 7.5

GHSA-xpp7-93x6-v29m

XSS in Ghost's ActivityPub client

Quick fix

GHSA-xpp7-93x6-v29m — @tryghost/activitypub: upgrade to the fixed version with the command below.

npm install @tryghost/activitypub@3.1.0

Details

### Impact

The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server.

### Vulnerable Versions

This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected.

### Patches

@tryghost/activitypub v3.1.0 contains a fix for this issue and is also automatically fetched by Ghost.

### References

Ghost thanks Brad Geesaman, Ghost Security for disclosing this vulnerability responsibly.

### For more information

If you have any questions or comments about this advisory, email Ghost at [security@ghost.org](mailto:security@ghost.org).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @tryghost/activitypub
Introduced in: 0 Fixed in: 3.1.0
Fix npm install @tryghost/activitypub@3.1.0

References