@fedify@hollo.social · Reply to jer
@nyquildotorg Yeah, they seemed to already update their version of Fedify!
https://github.com/TryGhost/ActivityPub/commit/6fafc7d224b1c9a8b21833769a0dc9d884781fe8
Fixed inbox signature verification · TryGhost/ActivityPub@6fafc7d
ref https://github.com/fedify-dev/fedify/discussions/361 This patches a hole in the signature verification in Fedify which allowed impersonation of actors.