Sceawere
Vulnerability Detail
CVE-2026-105650UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ghost Stored Cross-Site Scripting
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 1h ago
- Vendor
- TryGhost
- Product
- Ghost
- Attack Type
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting in compromise of a staff user's admin session. This issue is fixed in version 6.64.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-05T20:17:13.817Z",
"pubdate": "2026-10-05T20:17:13.817Z",
"executiveSummary": "This vulnerability is a Stored Cross-Site Scripting (XSS) flaw identified within the Ghost Node.js content management system. The issue arises from improper neutralization of user-supplied input when embedding external URLs into post content. By embedding a crafted URL from an attacker-controlled domain, an adversary can inject malicious scripts that persist within the Ghost database.\nThe vulnerability affects Ghost versions 2.1.0 through 6.64.0. Successful exploitation allows for the execution of arbitrary JavaScript within the context of the victim's session, including staff users accessing the Ghost editor, visitors viewing the published site, and recipients of automated newsletter emails.\nThe risk implication is significant, as it facilitates unauthorized session compromise, potential administrative account takeover, and data exfiltration. Attackers do not necessarily require specialized privileges to embed content if the platform permits public or contributor submissions, making the attack surface broad. This vulnerability has been remediated in version 6.64.0, which enforces stricter input sanitization protocols for external URL embeddings.",
"technicalDetails": "The root cause of this vulnerability lies in an inadequate sanitization and validation mechanism for external resource embedding within the Ghost post editor. When a user embeds an external URL, the application fails to sufficiently sanitize the metadata or the resulting HTML representation derived from that URL, allowing malicious scripts to be injected into the persistent storage of the CMS.\nThe attack flow follows a structured pattern: 1) The attacker prepares an external website designed to serve malicious JavaScript payloads, often disguised or obfuscated within Open Graph tags or metadata fetched by the Ghost server. 2) The attacker embeds the URL of this controlled website into a post within the Ghost editor. 3) The Ghost server retrieves the URL and stores the malicious script within the post content in the database. 4) The payload is then rendered globally; it triggers when an administrative user opens the editor to view the post, when a legitimate end-user accesses the published post via a web browser, or when the newsletter service parses the malicious HTML to distribute emails.\nThe vulnerable component involves the URL embedding/oEmbed processing module within Ghost's post-processing pipeline. Because the application blindly trusts or insufficiently sanitizes the response retrieved from the attacker-controlled URL before storing it as part of the content entity, the application effectively becomes a delivery vehicle for stored XSS payloads. Once persisted, the malicious JavaScript executes within the victim's browser session. If a staff user with administrative privileges views the corrupted post, the payload can perform requests to the Ghost API, capture session cookies, or modify the CMS environment, leading to full site compromise.\nThe scope of impact is extensive due to the cross-platform nature of the rendered output. By leveraging this XSS primitive, an attacker can bypass Content Security Policy (CSP) headers if they are not strictly enforced, or exploit the lack of HttpOnly flags on session tokens. This allows for persistent, multi-stage attacks that propagate from the CMS backend to the frontend and email delivery systems. Version 6.64.0 addresses this by implementing improved input sanitization routines that effectively strip or neutralize executable scripts before they are committed to the data store."
}