GHSA-xpp7-93x6-v29m: XSS
Impact
The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server.
Vulnerable Versions
This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected.
Patches
@tryghost/activitypub v3.1.0 contains a fix for this issue and is also automatically fetched by Ghost.
References
Ghost thanks Brad Geesaman, Ghost Security for disclosing this vulnerability responsibly.
For more information
If you have any questions or comments about this advisory, email Ghost at security@ghost.org.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@tryghost/activitypubto a version that resolves this vulnerability.Fixed in 3.1.0 - Upgrade
Upgrade
@tryghost/activitypubto a version that resolves this vulnerability.Fixed in v3.1.0
Event History
Frequently Asked Questions
What is the severity of GHSA-xpp7-93x6-v29m?
GHSA-xpp7-93x6-v29m has a severity rating of high with a score of 7.5.
What impact does GHSA-xpp7-93x6-v29m have?
GHSA-xpp7-93x6-v29m allows for JavaScript injection via posts shared by a maliciously customized ActivityPub server.
How do I fix GHSA-xpp7-93x6-v29m?
To fix GHSA-xpp7-93x6-v29m, upgrade the @tryghost/activitypub package to version 3.0.9 or later.
Which versions are affected by GHSA-xpp7-93x6-v29m?
All versions of the @tryghost/activitypub package up to and including v3.0.8 are affected by GHSA-xpp7-93x6-v29m.
What type of vulnerability is GHSA-xpp7-93x6-v29m?
GHSA-xpp7-93x6-v29m is classified as a Cross-Site Scripting (XSS) vulnerability.