Sceawere
Vulnerability Detail
CVE-2026-105642UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ghost SVG Remote Code Execution
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 2h ago
- Vendor
- TryGhost
- Product
- Ghost
- Attack Type
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attacker-controlled website, resulting in arbitrary commands being run on the Ghost server. This issue is fixed in version 6.67.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-05T19:17:18.733Z",
"pubdate": "2026-10-05T19:17:18.733Z",
"executiveSummary": "A critical vulnerability exists within an image processing library bundled with Ghost versions 6.56.0 through 6.67.0. The vulnerability allows for Remote Code Execution (RCE) on the underlying server through the mishandling of malicious SVG content. The issue manifests when a staff user, holding at least Contributor-level privileges, creates a bookmark card referencing an attacker-controlled website. This allows the attacker to achieve arbitrary command execution, effectively compromising the confidentiality, integrity, and availability of the host server. Given the nature of the vulnerability, it presents a high risk to Ghost deployments, as it allows for privilege escalation from a legitimate, albeit low-privileged, user account to full server-level command execution. No external network exposure is strictly required beyond the ability for the server to process the malicious SVG metadata fetched during the bookmark card creation process.",
"technicalDetails": "The vulnerability resides in the third-party image processing library integrated into the Ghost CMS, specifically within the module responsible for parsing and processing Scalable Vector Graphics (SVG). The flaw is triggered when the application fetches metadata or generates a preview for a bookmark card pointing to an external domain. When a user creates a bookmark card, the Ghost server initiates a request to the provided URL to extract metadata. If the target website serves a crafted malicious SVG file—or if the metadata fetch involves processing a malicious SVG payload—the library fails to safely sanitize the input.\nThe root cause is an insecure implementation in the SVG parsing logic, which facilitates command injection or object injection patterns that reach the underlying system shell. Because the library processes these images server-side to generate thumbnails or verify content, it inadvertently executes embedded malicious directives contained within the SVG structure.\nThe attack flow proceeds as follows: 1. A user with Contributor privileges (or higher) creates a new bookmark card within the Ghost admin interface, specifying an attacker-controlled URL as the source. 2. Ghost's backend service triggers an asynchronous task to fetch the metadata from the provided URL. 3. The bundled image processing library parses the response from the remote server. 4. Upon encountering the maliciously crafted SVG, the parser performs unsafe operations that interpret data fields as executable system commands. 5. The operating system executes these commands with the privileges of the Node.js process running the Ghost instance. 6. The attacker achieves arbitrary code execution, enabling them to gain a foothold on the server, exfiltrate sensitive database configuration files, pivot to internal network segments, or install persistent backdoors. Because the process occurs at the server level during the content creation workflow, the vulnerability bypasses front-end browser-side security controls. The exploitation is inherently linked to the library's inability to isolate and sandbox SVG parsing tasks, rendering the server susceptible whenever an administrative user interacts with external bookmark sources."
}