In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @fedify/fedify to version 1.9.11, 1.10.10, 2.0.18, 2.1.14, 2.2.3 or higher.
@fedify/fedify is an An ActivityPub server framework
Affected versions of this package are vulnerable to Incorrect Behavior Order: Validate Before Canonicalize through manipulation of JSON-LD document structure using keywords such as @graph, @included, and @reverse. An attacker can alter the interpretation of signed activities, potentially modifying or removing attributes, replaying activities, or forging arbitrary content by restructuring the payload while preserving its signature. This can result in unauthorized changes to activity data, loss of integrity, and disruption of service by exploiting the way the application processes and verifies signed JSON-LD documents.