Impact
Ghost versions from 0.5.3 up to but excluding 6.50.0 do not properly escape content inserted by the ghost_head helper. An authenticated user with limited privileges can inject unescaped JavaScript into the JSON-LD <script> tag that is emitted by the template. When a staff user with an admin session views the injected page, the malicious script executes in that session, potentially allowing the attacker to hijack the admin session or perform other actions on behalf of the staff user.
Affected Systems
Affected: Ghost content management system developed by TryGhost. Vulnerable releases include 0.5.3 through every build prior to version 6.50.0. Any installation using these releases without the patch is exposed to this injection vector.
Risk and Exploitability
The CVSS score of 8.6 signals a high severity vulnerability. The exploit requires an authenticated attacker, but only with low privileges, and relies on the ghost_head template helper. Because a compromised staff session compromises the entire site’s administrative control, the impact is significant. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, yet the potential for credential compromise justifies urgent attention.
OpenCVE Enrichment