PT-2026-106138 · Ghost · Ghost
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ghost versions 6.56.0 through 6.66.0
Description
A vulnerability exists in the SVG handling of an image processing library bundled with the Ghost content management system. A staff user with Contributor permissions or higher can create a bookmark card for a website controlled by an attacker, which allows the execution of arbitrary commands on the Ghost server.
Recommendations
Update to version 6.67.0.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ghost