Sceawere

Vulnerability Detail

CVE-2026-105643UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ghost Stored XSS in Embeds

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
2h ago
Vendor
TryGhost
Product
Ghost
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections against stored cross-site scripting. Any staff user, including Contributors, could store scripts in post content that ran when another staff user opened the post in the editor, potentially compromising that user’s admin session. Self-hosted sites should leave the new  security.embedPreviewUrl  configuration option at its default value. This issue is fixed in version 6.67.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T19:17:18.900Z",
  "pubdate": "2026-10-05T19:17:18.900Z",
  "executiveSummary": "A stored Cross-Site Scripting (XSS) vulnerability exists within the Ghost content management system, specifically affecting the embed card functionality in the editor.\nThe vulnerability allows authenticated staff users, including those with minimal privileges such as Contributors, to inject and store malicious scripts within post content.\nWhen a victimized staff user opens the compromised post within the Ghost editor interface, the embedded script executes within their browser context.\nSuccessful exploitation can lead to full administrative session compromise, enabling attackers to perform unauthorized actions on behalf of the victim.\nThis vulnerability impacts self-hosted and managed Ghost instances running versions 6.34.0 through 6.66.0.\nThe primary risk is privilege escalation or unauthorized administrative access by internal users. Mitigation requires upgrading to version 6.67.0 or later and ensuring the security.embedPreviewUrl configuration remains at its default secure setting.",
  "technicalDetails": "The vulnerability is a stored XSS flaw residing in the Ghost editor's handling of embed cards. The root cause is an improper sanitization or validation failure of user-supplied data processed by the embed preview mechanism.\nAttackers with at least 'Contributor' level access can craft malicious embed card parameters. By inputting a crafted payload into the post editor, the attacker successfully persists the script in the Ghost database.\nThe attack flow follows these steps: 1) The attacker creates or edits a post using the Ghost editor. 2) The attacker inserts an embed card, manipulating the metadata or preview URL parameters to include an XSS payload. 3) The payload is stored as part of the post content. 4) When an unsuspecting staff user (e.g., an Editor or Administrator) accesses the post within the admin interface, the application renders the malicious embed card content.\nDuring the rendering process in the editor, the application fails to adequately sanitize the embed preview source, leading to the execution of the injected JavaScript in the victim's browser session. Because the script executes within the admin panel's origin, it inherits the session's privileges.\nThe post-exploitation impact includes the potential for session hijacking, unauthorized API requests, or the injection of further malicious content into the CMS. Since Ghost relies on session-based cookies for authentication, the script can access sensitive headers or perform actions that modify site configuration or content without the victim's consent.\nThe vulnerable component is the embed card rendering logic within the Ghost admin interface. Affected versions include 6.34.0 to 6.66.0. The exploit requires authentication as a valid system user, making this a significant insider threat risk within multi-user Ghost deployments.\nThe fix introduced in 6.67.0 addresses the inadequate sanitization and introduces a more secure handling of embed previews. Additionally, the introduction of the security.embedPreviewUrl configuration serves as a control mechanism to limit where or how these previews are fetched and rendered, mitigating the risk of arbitrary script execution via malicious URLs."
}
CVE-2026-105643: Ghost Stored XSS in Embeds (HIGH Severity, CVSS: 7.3) | Sceawere