CVE-2026-105643
Received Received - Intake

Stored XSS in Ghost CMS Editor via Embed Cards

Vulnerability report for CVE-2026-105643, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections against stored cross-site scripting. Any staff user, including Contributors, could store scripts in post content that ran when another staff user opened the post in the editor, potentially compromising that user’s admin session. Self-hosted sites should leave the new  security.embedPreviewUrl  configuration option at its default value. This issue is fixed in version 6.67.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
TryGhost Ghost >= 6.34.0, < 6.67.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-653 The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105643 is a stored cross-site scripting (XSS) vulnerability in Ghost CMS versions 6.34.0 to 6.65.0. It allows staff users, including Contributors, to inject malicious scripts into post content via embed cards. When another staff member opens the post in the editor, the script executes, potentially compromising their admin session.

Detection Guidance

To detect this vulnerability, check if your Ghost CMS version is between 6.34.0 and 6.65.0. Use the command: ghost version. If the version is within this range, the system is vulnerable.

Impact Analysis

This vulnerability could allow an attacker with staff access to steal admin session cookies or perform actions on behalf of other staff users. It compromises the security of the Ghost CMS admin interface and could lead to unauthorized access or data breaches.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements for data protection and access controls. Organizations using affected Ghost versions may face compliance violations and potential legal consequences.

Mitigation Strategies

Immediately update Ghost CMS to version 6.67.0 or later. For Docker-based installations, pull the latest image and restart the container. For Ghost-CLI installations, run: ghost update.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105643. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart