Sceawere

Vulnerability Detail

CVE-2026-105649UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ghost SVG Stored XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
1h ago
Vendor
TryGhost
Product
Ghost
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.65.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T20:17:13.613Z",
  "pubdate": "2026-10-05T20:17:13.613Z",
  "executiveSummary": "A stored Cross-Site Scripting (XSS) vulnerability exists within the Ghost content management system, specifically impacting SVG media thumbnails and SVG files uploaded with non-SVG extensions. This vulnerability allows an authenticated attacker to inject and execute arbitrary JavaScript code within the context of the site's origin.\nThe flaw stems from a lack of proper sanitization during the file processing and storage phase. By bypassing file extension validation, an attacker can persist malicious SVG payloads on the server. When these files are accessed, the embedded scripts execute within the browser session of other users, including administrators.\nThe primary impact is the potential compromise of sensitive administrative sessions, leading to unauthorized account takeover, data exfiltration, or modification of site content. This vulnerability affects Ghost versions 4.22.0 through 6.65.0. Successful exploitation requires an authenticated user account with at least 'Contributor' privileges. The risk is significant due to the ease of payload delivery and the potential for lateral movement within the administrative dashboard.\nOrganizations using affected versions of Ghost are at high risk of unauthorized script execution until the system is updated to version 6.65.0 or later, which implements the necessary sanitization logic to neutralize malicious embedded content.",
  "technicalDetails": "The vulnerability is characterized as an unrestricted file upload leading to Stored Cross-Site Scripting (XSS). The root cause lies in the application's failure to perform adequate input validation and server-side sanitization on SVG media files and thumbnails processed during the upload workflow.\nThe attack vector involves the deliberate misrepresentation of malicious SVG files. Because the application fails to validate the internal structure and content of the uploaded files against their provided or detected MIME types, an attacker can upload a crafted SVG file containing malicious <script> or <foreignObject> elements designed to execute JavaScript upon rendering.\nBy assigning a non-SVG file extension, attackers can potentially evade basic client-side or perimeter-based file extension blacklists. Once stored, these files are hosted directly on the application's origin domain. The lack of Content Security Policy (CSP) enforcement or rigid file sanitization allows the browser to interpret these files as active content rather than static media, triggering the execution of the embedded script in the security context of the Ghost administrative interface.\nThe attack flow follows a structured path: 1. An attacker, authenticated with at least 'Contributor' privileges, initiates an image upload request to the Ghost server. 2. The attacker provides a malicious SVG file, potentially disguised with an alternative file extension. 3. The server-side processing component fails to sanitize the XML/SVG structure, storing the payload in the site's media storage directory. 4. The attacker induces a target user (e.g., an administrator) to view the media file or thumbnail. 5. The target's browser renders the SVG, causing the embedded malicious payload to execute. 6. The script utilizes the target's session cookies or authentication tokens to perform unauthorized administrative actions, such as changing settings or creating new administrative accounts, thus achieving persistent compromise.\nThis vulnerability is present in Ghost versions 4.22.0 through 6.65.0. It requires a valid, authenticated session, but the low privilege requirement of a 'Contributor' account significantly broadens the attack surface within an organization's internal team. The post-exploitation phase typically involves leveraging the XSS payload to perform Cross-Site Request Forgery (CSRF) or session hijacking against users with higher administrative privileges."
}
CVE-2026-105649: Ghost SVG Stored XSS Vulnerability (HIGH Severity, CVSS: 7.3) | Sceawere