Sceawere
Vulnerability Detail
CVE-2026-105645UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ghost Media Inliner DoS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.9
- Creation Date
- 2h ago
- Vendor
- TryGhost
- Product
- Ghost
- Attack Type
- CWE-1333: Inefficient Regular Expression Complexity
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Ghost is a Node.js content management system. From 5.37.0 until 6.67.0, a crafted request to the external media inliner could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.9",
"pubDate": "2026-10-05T19:17:19.223Z",
"pubdate": "2026-10-05T19:17:19.223Z",
"executiveSummary": "A Denial of Service (DoS) vulnerability exists within the Ghost content management system due to inefficient resource handling in the external media inliner component.\nThe vulnerability allows an authenticated Administrator to trigger excessive CPU consumption by submitting a maliciously crafted request to the affected inliner.\nSuccessful exploitation results in the exhaustion of server processing resources, leading to service unresponsiveness and rendering the Ghost instance unavailable to legitimate users.\nThe flaw affects Ghost versions 5.37.0 through 6.66.0.\nExploitation is strictly constrained by a requirement for administrative-level privileges, limiting the threat vector to malicious insiders or compromised administrative accounts.\nThe issue has been resolved in version 6.67.0 through performance optimizations and input sanitization.\nOrganizations are advised to upgrade to the latest stable release to mitigate the risk of resource exhaustion attacks.",
"technicalDetails": "The vulnerability resides within the external media inliner, a utility responsible for fetching and processing remote media assets during content creation or management workflows.\nThe root cause is an improper handling of specific input parameters during the media inlining process, which leads to an algorithmic complexity issue when parsing or processing the crafted request.\nWhen a specially crafted payload is submitted to the media inliner, the Ghost application enters an uncontrolled loop or performs redundant, resource-intensive operations that consume significant CPU cycles.\nAttack Flow: 1. An attacker with Administrator privileges authenticates to the Ghost administrative interface. 2. The attacker triggers a request to the external media inliner, supplying a payload designed to trigger the identified processing inefficiency. 3. The server-side component attempts to process the media asset, initiating the intensive calculation task. 4. The underlying Node.js event loop becomes blocked due to the sustained CPU load caused by the inliner task. 5. As the CPU remains pinned at maximum utilization, the server fails to respond to concurrent requests, effectively crashing or hanging the application process.\nThe impact is a complete denial of service for the affected Ghost instance, as the process becomes unresponsive to network traffic during the execution of the crafted payload.\nThe vulnerability is limited to the media inliner component and requires an established administrative session, as unauthenticated users lack the necessary access to invoke the vulnerable function.\nBecause Node.js is single-threaded, the high CPU usage induced by this vulnerability effectively halts the event loop, preventing the server from handling asynchronous I/O operations and blocking all incoming requests from other clients.\nThe issue is specific to the handling of external resources, meaning that network connectivity between the Ghost server and external endpoints might be a prerequisite for the payload to reach the vulnerable processing logic."
}