PT-2026-106185 · Ghost · Ghost

·

CVE-2026-105651

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Ghost versions 5.94.0 through 6.63.0
Description Ghost, a Node.js content management system, allows staff users, including those with Contributor roles, to host arbitrary HTML on the site domain. This occurs when creating a bookmark card, as the system may store non-image files fetched from external websites as bookmark icons or thumbnails. This behavior could lead to the compromise of administrative sessions of other staff users.
Recommendations Update Ghost to version 6.64.0.

Exploit

Fix

XSS

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105651
GHSA-347Q-26QQ-H2P6

Affected Products

Ghost