GHSA-xpp7-93x6-v29m
XSS in Ghost's ActivityPub client
Quick fix
GHSA-xpp7-93x6-v29m — @tryghost/activitypub: upgrade to the fixed version with the command below.
npm install @tryghost/activitypub@3.1.0 Details
### Impact
The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server.
### Vulnerable Versions
This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected.
### Patches
@tryghost/activitypub v3.1.0 contains a fix for this issue and is also automatically fetched by Ghost.
### References
Ghost thanks Brad Geesaman, Ghost Security for disclosing this vulnerability responsibly.
### For more information
If you have any questions or comments about this advisory, email Ghost at [security@ghost.org](mailto:security@ghost.org).
Are you affected?
Enter the version of the package you're using.
Affected packages
0 Fixed in: 3.1.0 npm install @tryghost/activitypub@3.1.0