PT-2026-106183 · Ghost · Ghost

·

CVE-2026-105649

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Ghost versions 4.22.0 through 6.64.0
Description SVG media thumbnails and SVG images uploaded with a non-SVG file extension are stored without sanitization. This allows staff users, including those with Contributor roles, to host malicious scripts on the site domain, which could lead to the compromise of administrative sessions of other staff users.
Recommendations Update to version 6.65.0.

Exploit

Fix

XSS

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105649
GHSA-8575-CR6V-7JH4

Affected Products

Ghost