Impact
Ghost versions from 2.5.0 through 6.33.x contain an untrusted script execution flaw in the oEmbed preview feature that does not sandbox externally hosted scripts. When an attacker supplies malicious oEmbed content, the embedded script runs in the context of an authenticated staff user’s admin session, giving the attacker the ability to execute arbitrary JavaScript and potentially compromise administrative access.
Affected Systems
The affected product is Ghost released by TryGhost, encompassing all public releases from 2.5.0 up to but not including 6.34.0.
Risk and Exploitability
The vulnerability has a CVSS score of 8.6, indicating high severity. EPSS data is not available and the flaw is not listed in the CISA KEV catalog. An attacker can exploit the issue by crafting and distributing malicious oEmbed content, likely through third‑party services or content editors, resulting in script execution that could lead to privilege escalation or arbitrary code execution within the admin environment.
OpenCVE Enrichment