PT-2026-106177 · Ghost · Ghost

·

CVE-2026-105643

·

Published

2026-10-05

·

Updated

2026-10-07

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Ghost versions 6.34.0 through 6.66.0
Description Embed cards in the editor allow staff users, including those with Contributor roles, to bypass protections against stored cross-site scripting (XSS). This occurs when scripts are stored in post content and subsequently execute when another staff user opens the post in the editor, which could lead to the compromise of that user's admin session.
Recommendations Update to version 6.67.0. Maintain the security.embedPreviewUrl configuration option at its default value for self-hosted sites.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105643
GHSA-69QC-F5M6-889C
GHSA-QVQ5-C536-PMX8

Affected Products

Ghost