CVE-2026-105650
Received Received - Intake

Stored XSS in Ghost CMS via Malicious URL Embedding

Vulnerability report for CVE-2026-105650, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting in compromise of a staff user's admin session. This issue is fixed in version 6.64.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
TryGhost Ghost >= 2.5.0, < 6.64.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Stored Cross-Site Scripting (XSS) issue in Ghost CMS. It allows attackers to embed malicious scripts in post content by including a URL from a controlled website. The stored scripts can execute in the Ghost editor, published site, and newsletter emails, potentially compromising staff admin sessions.

Detection Guidance

Check Ghost CMS version with: npm list ghost or ghost version. If version is below 6.64.0, the system is vulnerable. Inspect post content for unexpected scripts or HTML in oEmbed responses from untrusted sources.

Impact Analysis

The impact includes potential compromise of staff admin sessions, allowing attackers to gain unauthorized access. The scripts can run in multiple contexts like the editor, published site, and emails, posing risks to data confidentiality and integrity.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. The stored XSS could allow attackers to steal session tokens or sensitive data, compromising confidentiality and integrity of user data.

Mitigation Strategies

Upgrade Ghost CMS to version 6.64.0 or later immediately. Review and remove any suspicious scripts in post content. Restrict oEmbed providers to trusted domains only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105650. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart