Sceawere
Vulnerability Detail
CVE-2026-104413UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Ghost Bookmark
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 11h ago
- Vendor
- TryGhost
- Product
- Ghost
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to host arbitrary HTML by abusing bookmark card image fetching. Attackers can create bookmark cards that store non-image files from external websites as icons or thumbnails to compromise other staff users' admin sessions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-02T12:17:10.980Z",
"pubdate": "2026-10-02T12:17:10.980Z",
"executiveSummary": "A stored cross-site scripting (XSS) vulnerability exists in Ghost versions 5.94.0 through 6.64.0, originating from improper handling of bookmark card image fetching.\nThe vulnerability allows authenticated staff users, including those with minimal 'Contributor' privileges, to inject and execute arbitrary HTML within the context of the administrative interface.\nBy manipulating the bookmark card metadata, an attacker can force the application to fetch non-image assets from external sources, which are subsequently rendered by the browser.\nThe primary impact is the potential compromise of administrative sessions, enabling attackers to perform unauthorized actions, access sensitive data, or escalate privileges within the Ghost management environment.\nThis vulnerability highlights a flaw in the trust boundary between the server-side image retrieval process and the client-side rendering engine.\nExploitation requires active authentication as a staff user but does not necessarily require additional configuration beyond creating a crafted bookmark card.\nOrganizations using affected versions are at risk of lateral movement and account takeover if an attacker with low-level access crafts a malicious payload targeting higher-privileged users such as Administrators or Owners.",
"technicalDetails": "The vulnerability resides within the bookmark card feature of Ghost, specifically in the logic responsible for fetching and displaying metadata, icons, or thumbnails from external URLs.\nThe root cause is the lack of strict content-type validation and sanitization during the retrieval and subsequent rendering of images associated with bookmark cards.\nWhen a user creates a bookmark card, Ghost attempts to scrape the provided URL to extract metadata. The application fails to adequately sanitize the source data, allowing an attacker to point the bookmark card toward an attacker-controlled external endpoint that serves malicious non-image files (e.g., HTML files masquerading as assets or content with embedded malicious scripts).\nBecause the platform improperly handles these external assets, the injected HTML or JavaScript is rendered directly within the administrative dashboard when a victimized staff user views the affected bookmark card.\nThe attack flow follows a specific progression: First, the attacker, possessing at least 'Contributor' privileges, identifies an external source or hosts a malicious file that mimics an image metadata response. Second, the attacker creates a bookmark card within Ghost, providing the URL to the malicious endpoint. Third, the Ghost server performs a fetch operation for the bookmark's metadata/image. Fourth, the server saves the malicious payload within the application's data storage. Finally, when an administrator or another staff user views the content containing the bookmark card, the browser executes the stored XSS payload in the context of the user's active session.\nThe execution of the script occurs within the victim's authenticated session, granting the attacker the same level of access as the victim. This enables a wide range of post-exploitation actions, including the exfiltration of session cookies, CSRF-based account modification, or the injection of persistent backdoors via administrative API calls.\nThe vulnerability affects versions 5.94.0 to 6.64.0. The lack of Content Security Policy (CSP) enforcement on the bookmark rendering component, combined with insufficient output encoding, allows for the bypass of standard XSS protections within the admin panel interface.\nExploitation is facilitated by the application's automated background process that fetches remote data without enforcing strict MIME-type checks or sandboxing the rendered thumbnail content."
}