Sceawere

Vulnerability Detail

CVE-2026-104414UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ghost Stored XSS via oEmbed

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
11h ago
Vendor
TryGhost
Product
Ghost
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embedding their URL stores scripts that run in the Ghost editor, published site, and newsletter emails, compromising staff admin sessions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-10-02T12:17:11.127Z",
  "pubdate": "2026-10-02T12:17:11.127Z",
  "executiveSummary": "A stored cross-site scripting (XSS) vulnerability exists in Ghost versions 2.5.0 through 6.63.1, originating from improper sanitization of oEmbed photo response data. This flaw allows an attacker to inject malicious scripts into post content by leveraging external oEmbed providers. When the application fetches metadata from an attacker-controlled URL, the unsanitized script is stored within the platform’s database. Subsequent rendering of the post in the Ghost editor, the published front-end site, or within generated newsletter emails triggers the execution of the payload. The impact is critical, as it facilitates the compromise of staff administrator sessions, potentially leading to full site takeover, unauthorized data access, and unauthorized content modification. Successful exploitation requires the ability to host a malicious oEmbed response, which is then embedded within a Ghost post. This vulnerability poses a severe risk to content integrity and administrative security, necessitating an immediate update to the patched versions.",
  "technicalDetails": "The vulnerability resides in how Ghost processes and persists data retrieved from oEmbed endpoints. Ghost utilizes an oEmbed implementation to convert URLs into rich media previews. The technical root cause is an insufficient input sanitization process when handling the 'photo' type response from an oEmbed-compliant provider. Specifically, the application fails to adequately encode or sanitize metadata attributes returned by the remote server, allowing for the injection of arbitrary JavaScript payloads.\nThe attack flow follows a structured trajectory: First, an attacker establishes a malicious oEmbed provider endpoint that returns a crafted JSON response containing a 'type': 'photo' attribute. Within this JSON, the attacker injects malicious JavaScript tags into fields expected to be rendered by the Ghost client, such as the 'url', 'title', or 'author_name' attributes. Second, the attacker embeds the URL of this malicious endpoint into a Ghost post via the editor interface. Third, the Ghost system performs an asynchronous fetch to the attacker-controlled URL to retrieve metadata. Because the system trusts the returned metadata, it persists the malicious payload directly into the database as part of the post content.\nThe exploitation is finalized upon rendering. When an administrator or user views the post—either within the Ghost editor, the public-facing website, or via an email client consuming the newsletter content—the victim's browser or mail client executes the injected script. Because the script runs within the context of the victim's session, the attacker can leverage the browser's access to cookies, local storage, and the DOM. This results in the exfiltration of administrative session tokens, the creation of rogue administrator accounts, or the mass distribution of malicious content across the site.\nThis vulnerability is classified as stored XSS due to the persistence of the payload in the application's database. It affects the Ghost editor, the front-end rendering engine, and the newsletter service, effectively bypassing security boundaries intended to isolate user-submitted content. Given the broad exposure of these components, the exploit surface spans from internal administrative panels to external public audiences."
}
CVE-2026-104414: Ghost Stored XSS via oEmbed (HIGH Severity, CVSS: 8.1) | Sceawere