CVE-2026-103292
Received Received - Intake

Ghost Head Template XSS via JSON-LD Injection

Vulnerability report for CVE-2026-103292, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted by the {{ghost_head}} helper. An authenticated user with limited privileges can inject unescaped content that is rendered as script in the published page, potentially leading to compromise of a staff user's admin session when that user views the affected page.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ghost ghost From 0.5.3 (inc) to 6.50.0 (exc)
tryghost ghost From 0.5.3 (inc) to 6.50.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Ghost CMS versions from 0.5.3 to before 6.50.0. It involves improper sanitization of data in the JSON-LD HTML tag generated by the {{ghost_head}} helper. An authenticated user with limited privileges can inject unescaped content that executes as script when rendered on a published page, potentially compromising a staff user's admin session.

Detection Guidance

To detect this vulnerability, check your Ghost CMS version. If it is between 0.5.3 and below 6.50.0, it is vulnerable. Use commands like 'ghost version' or check your package.json for Ghost version. Inspect pages using {{ghost_head}} for unexpected script tags in JSON-LD output.

Impact Analysis

An attacker could inject malicious scripts into pages viewed by staff users. If an admin views the affected page, their session could be compromised, leading to unauthorized access or control of the Ghost CMS instance.

Compliance Impact

This XSS vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality requirements. For HIPAA, it may risk protected health information exposure. Compliance could be compromised if user data is accessed or altered due to the vulnerability.

Mitigation Strategies

Immediately update Ghost CMS to version 6.50.0 or later. Remove or restrict access for untrusted users who could inject malicious content. Monitor admin sessions for unusual activity after updating.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103292. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart