Sceawere

Vulnerability Detail

CVE-2026-105646UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ghost CMS Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.9
Creation Date
2h ago
Vendor
TryGhost
Product
Ghost
Attack Type
CWE-1333: Inefficient Regular Expression Complexity
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, a crafted content import file could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.9",
  "pubDate": "2026-10-05T19:17:19.373Z",
  "pubdate": "2026-10-05T19:17:19.373Z",
  "executiveSummary": "This vulnerability is a Denial of Service (DoS) flaw affecting the Ghost CMS platform, specifically within the content import functionality. The flaw allows an authenticated user with Administrator privileges to trigger excessive CPU consumption, effectively rendering the application server unresponsive.\nThe vulnerability exists in all Ghost versions from 4.0.0 up to, but not including, 6.67.0. The impact is significant as it disrupts service availability for all users of the affected instance.\nExploitation requires the attacker to possess Administrator-level credentials, which constrains the attack surface to malicious insiders or compromised administrative accounts. The primary risk implication is the forced cessation of operations due to resource exhaustion, requiring administrative intervention or service restart to recover availability.\nNo external network access beyond what is required for legitimate administration is necessary for exploitation, provided the attacker has already obtained the requisite privileges to interface with the content import subsystem.",
  "technicalDetails": "The vulnerability is rooted in an improper handling of crafted content import files during the ingestion process within Ghost CMS. When a user with Administrator privileges initiates a content import, the application processes the provided data structure. A maliciously crafted file exploits a flaw in the parsing or processing logic, leading to a computational complexity spike that consumes excessive CPU cycles.\nThe attack flow commences when an authenticated administrator navigates to the administrative interface and accesses the content import feature. The attacker uploads a specifically structured file designed to trigger an inefficient algorithmic path within the import processing module. Upon ingestion, the Ghost server's Node.js event loop becomes saturated with the compute-intensive operations required to parse the malformed data.\nBecause Node.js operates on a single-threaded event loop architecture, the excessive CPU usage caused by the exploit blocks the execution of all other tasks, including incoming HTTP requests and background processes. This leads to a total service outage for the application, as the process can no longer respond to legitimate user traffic. The resource exhaustion is persistent as long as the parsing process remains active or until the server process is forcibly terminated or restarted.\nThe vulnerability affects the core content import component of the Ghost platform for versions 4.0.0 through 6.67.0. The exploit does not require advanced network-level bypasses; it relies entirely on the legitimate administrative privilege set. By abusing the trust placed in the administrator's ability to import content, the payload forces the backend to perform operations that scale poorly in terms of time complexity. Post-exploitation impact is limited to a Denial of Service, as there is no indication that this specific vector facilitates remote code execution or unauthorized data exfiltration; however, the resulting instability effectively removes the CMS from the environment."
}
CVE-2026-105646: Ghost CMS Denial of Service (MEDIUM Severity, CVSS: 4.9) | Sceawere