Sceawere
Vulnerability Detail
CVE-2026-105651UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ghost Stored XSS via Bookmarks
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 1h ago
- Vendor
- TryGhost
- Product
- Ghost
- Attack Type
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from an external website as bookmark icons or thumbnails. This allowed any staff user, including Contributors, to host arbitrary HTML on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.64.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-05T20:17:14.010Z",
"pubdate": "2026-10-05T20:17:14.010Z",
"executiveSummary": "A stored cross-site scripting (XSS) vulnerability exists within the Ghost content management system, affecting versions 5.94.0 through 6.63.0. The flaw resides in the bookmark card feature, which improperly validates file types fetched from external URLs.\nBy manipulating the metadata retrieval process for bookmark icons or thumbnails, a low-privileged authenticated user, such as a Contributor, can force the system to store arbitrary non-image files, including malicious HTML, directly on the Ghost domain. This bypasses expected content filtering and allows for the execution of unauthorized scripts within the context of the administrative interface.\nThe primary impact is a full compromise of administrator or other staff user sessions via session hijacking or unauthorized administrative actions. Since the malicious content is served from the trusted site domain, security controls like Same-Origin Policy (SOP) offer no protection against the payload. The vulnerability is effectively neutralized in version 6.64.0, which implements stricter validation for remote assets retrieved by the bookmarking service.",
"technicalDetails": "The vulnerability originates from inadequate server-side validation of remote resources during the bookmark card creation process. When a user provides a URL for a bookmark, the Ghost server initiates a request to the target website to fetch metadata, specifically targeting the icon or thumbnail associated with the link.\nThe root cause is the failure of the media processing component to enforce strict MIME-type and content-validation checks on the fetched remote data. Rather than filtering for expected image formats (e.g., JPEG, PNG), the application accepts and persists arbitrary file types provided by the remote server. An attacker can host a malicious HTML file on an external server and point the Ghost bookmark feature to that resource. Upon processing, Ghost downloads the payload and stores it as a file object on its own infrastructure.\nThe attack flow follows a predictable sequence: First, the attacker, authenticated as a staff member with at least Contributor-level access, initiates the creation of a new bookmark card within the Ghost editor. Second, the attacker inputs a URL pointing to a malicious, attacker-controlled domain. Third, the Ghost server makes an out-of-bound HTTP request to the target URL. Fourth, the attacker's server responds with an HTML payload masquerading as an image file. Fifth, the vulnerable Ghost instance, lacking robust content validation, treats the payload as a legitimate asset and saves it to the local media directory.\nOnce stored, the malicious HTML is rendered within the context of the administrative panel when the bookmark is viewed or embedded. Because the content is served from the same domain as the Ghost administration console, the injected JavaScript executes with the permissions of the current viewer. If an administrator views the bookmark, the attacker can execute arbitrary code to perform administrative functions, exfiltrate sensitive session tokens, or modify site configuration. The vulnerability requires authenticated access to the Ghost editor, but the low privilege requirement allows any user with contributor rights to compromise the platform’s security integrity."
}