CVE-2026-105651
Received Received - Intake

Bookmark Card HTML Injection in Ghost CMS

Vulnerability report for CVE-2026-105651, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from an external website as bookmark icons or thumbnails. This allowed any staff user, including Contributors, to host arbitrary HTML on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.64.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
TryGhost Ghost >= 5.94.0, < 6.64.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Ghost CMS (versions 5.94.0 to 6.64.0) allowed staff users to upload non-image files like HTML or scripts as bookmark icons by manipulating URLs or Content-Type headers. The system would store these files and serve them with image MIME types, enabling potential malicious content execution on the site's domain.

Detection Guidance

Check Ghost version with: ghost version. If version is between 5.94.0 and 6.64.0, the system is vulnerable. Inspect bookmark card images for unexpected file types or HTML content. Review server logs for unusual file uploads or storage patterns.

Impact Analysis

An attacker with staff access could upload malicious HTML or scripts, compromising admin sessions or executing arbitrary code on the site. This could lead to data theft, defacement, or further attacks against users visiting the site.

Compliance Impact

This vulnerability could violate GDPR or HIPAA by enabling unauthorized access to sensitive data through compromised admin sessions or malicious content injection. It undermines data integrity and confidentiality requirements.

Mitigation Strategies

Upgrade Ghost to version 6.64.0 or later immediately. Remove any suspicious non-image files stored as bookmark icons. Restrict staff user permissions to prevent unauthorized file uploads. Monitor admin sessions for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105651. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart