Sceawere
Vulnerability Detail
CVE-2026-105644UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ghost SVG Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 2h ago
- Vendor
- TryGhost
- Product
- Ghost
- Attack Type
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in content imports were stored without sanitization. An attacker who convinced an Administrator to import a crafted file could host scripts on the site's domain, possibly resulting in compromise of staff users' admin sessions. This issue is fixed in version 6.67.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-05T19:17:19.060Z",
"pubdate": "2026-10-05T19:17:19.060Z",
"executiveSummary": "The Ghost content management system is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability due to insufficient sanitization of SVG images during the content import process.\nThis vulnerability affects Ghost versions 4.0.0 through 6.67.0.\nThe flaw allows an attacker to inject and host malicious scripts within the application's domain by leveraging the lack of input validation on imported SVG files.\nSuccessful exploitation requires an attacker to trick an administrator into importing a crafted file containing the malicious payload.\nOnce the payload is executed in the context of an administrator's browser session, the attacker may gain unauthorized access to administrative sessions, potentially leading to full site compromise, data exfiltration, or unauthorized administrative actions.\nThis vulnerability presents a high risk to the confidentiality, integrity, and availability of the affected Ghost installation.",
"technicalDetails": "The vulnerability resides in the content import module of the Ghost CMS, which failed to perform adequate sanitization on Scalable Vector Graphics (SVG) files during ingestion.\nSVG is an XML-based vector image format that supports embedded scripts and event handlers. When the application processed an import, it stored these files directly on the server without stripping executable content or validating the XML structure for malicious tags such as <script>, <foreignObject>, or event-based attributes like 'onload'.\nThe attack flow begins with the creation of a maliciously crafted SVG file containing JavaScript payloads hidden within the XML metadata or scripting elements. An attacker distributes this file, typically via social engineering, to a site administrator with permissions to import content into the Ghost environment.\nUpon the administrator importing the crafted file, the Ghost system persists the SVG onto the server's storage backend and associates it with the site's domain. When the administrator or any other authenticated staff user navigates to the location of the uploaded SVG, the browser renders the file as an image element or direct XML document.\nBecause the file is hosted on the application's origin, the browser executes the embedded script within the security context of the Ghost administrative panel. This bypasses typical Same-Origin Policy (SOP) protections, granting the injected script the ability to interact with the Document Object Model (DOM), access local storage, and retrieve sensitive session cookies or authentication tokens.\nThe primary impact involves session hijacking, where the attacker steals the session identifier of the administrative user. With this session, the attacker can perform any action the compromised administrator is permitted to do, including modifying site settings, injecting additional malicious content, modifying user accounts, or exporting sensitive database information.\nThe vulnerability is present in all versions from 4.0.0 up to 6.67.0. The lack of an integrated XML sanitizer for uploaded image assets allowed arbitrary script execution, representing a failure in the application's security boundary between untrusted user-supplied content and the administrative interface."
}