CVE-2026-105642
Received Received - Intake

Arbitrary Command Execution in Ghost CMS via SVG Bookmark Cards

Vulnerability report for CVE-2026-105642, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attacker-controlled website, resulting in arbitrary commands being run on the Ghost server. This issue is fixed in version 6.67.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
TryGhost Ghost >= 6.56.0, < 6.67.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a high-severity vulnerability in Ghost CMS versions 6.56.0 to 6.65.0 that allows remote code execution through bookmark card images. The issue occurs because an image processing library improperly handles SVG files, letting any staff user (including Contributors) inject malicious commands by creating a bookmark card pointing to an attacker-controlled site. This results in arbitrary command execution on the Ghost server.

Detection Guidance

Check Ghost CMS version with: docker exec ghost_blog ghost version or ghost version if using Ghost-CLI. If version is between 6.56.0 and 6.65.0, the system is vulnerable. Inspect bookmark cards for suspicious SVG images or external links.

Impact Analysis

An attacker could exploit this to run arbitrary commands on your Ghost server, potentially stealing data, installing malware, or disrupting services. Since any staff user can trigger the issue, internal users with limited access could also be leveraged by attackers to gain control of the system.

Compliance Impact

This vulnerability could lead to unauthorized access, data breaches, or system compromise, violating GDPR's data protection requirements and HIPAA's security rules. Organizations may face fines, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Update Ghost CMS to version 6.67.0 or later immediately. For Docker, pull the latest image and restart the container. For Ghost-CLI, run ghost update. Remove untrusted staff users temporarily if compromise is suspected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105642. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart