CVE-2026-105649
Received Received - Intake

SVG Image Upload XSS in Ghost CMS

Vulnerability report for CVE-2026-105649, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.65.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
TryGhost Ghost >= 4.22.0, < 6.65.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) flaw in Ghost CMS. It allowed staff users, including Contributors, to upload SVG files with non-SVG extensions. These files bypassed sanitization and were stored without proper validation. The issue existed between versions 4.22.0 and 6.64.0 and was fixed in 6.65.0.

Detection Guidance

Check Ghost CMS versions between 4.22.0 and 6.64.0 for SVG uploads with non-SVG extensions. Inspect uploaded files for mismatched extensions and MIME types. Review server logs for suspicious script execution or unauthorized admin actions.

Impact Analysis

An attacker could upload a malicious SVG file disguised as another file type. When viewed by other staff users, the script could execute in their browser, potentially stealing admin session cookies or performing actions on their behalf. This could lead to full site compromise or unauthorized access.

Compliance Impact

This vulnerability could violate GDPR by exposing user data through XSS attacks or HIPAA by compromising systems handling protected health information. It undermines security controls required by these regulations, potentially leading to data breaches and compliance violations.

Mitigation Strategies

Upgrade Ghost CMS to version 6.65.0 or later. Disable SVG uploads if not required. Implement strict file validation to check both extension and MIME type for all uploads. Monitor admin sessions for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105649. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart