Description
Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to host arbitrary HTML by abusing bookmark card image fetching. Attackers can create bookmark cards that store non-image files from external websites as icons or thumbnails to compromise other staff users' admin sessions.
Published: 2026-10-02
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting allowing staff users to run arbitrary HTML in the admin context
Action: Immediate Patch
AI Analysis

Impact

Ghost versions 5.94.0 through 6.63.x contain a stored cross‑site scripting vulnerability that allows staff users to host arbitrary HTML by exploiting the bookmark card image fetching logic. Attackers can create bookmark cards that store non‑image files from external websites as icons or thumbnails. When those bookmark cards are rendered by another staff user, the injected HTML is executed within the admin context, potentially giving the attacker access to that session or allowing further manipulation of site data.

Affected Systems

The vulnerability affects TryGhost's Ghost content management system. All installations of Ghost from version 5.94.0 up to but not including 6.64.0 are susceptible. The issue is present in any deployment that allows staff or contributors to create bookmark cards and does not restrict the type of content fetched for bookmark card images.

Risk and Exploitability

The CVSS base score is 8.5, indicating a high severity impact. The EPSS score for this vulnerability is not available, and it is not listed in the CISA KEV catalog. The attack vector is a stored XSS that can be exploited by an attacker who can create or modify bookmark cards, which is generally achievable by any staff or contributor role. Once exploited, the attacker can run arbitrary JavaScript in the context of other staff users’ admin sessions, leading to session hijacking or data tampering. Because the flaw is fully exploitable through normal application usage, the risk to affected deployments is substantial, especially where staff have broad permissions and external image URLs are not sanitized.

Generated by OpenCVE AI on October 2, 2026 at 12:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.64.0 or later, which removes the vulnerable image‑fetching logic.
  • If an upgrade is not immediately possible, disable the ability for bookmark cards to retrieve external resources by configuring the image policy or setting a whitelist of allowed domains.
  • Review existing bookmark cards and remove any that reference non‑image files or external URLs until the fix is applied.

Generated by OpenCVE AI on October 2, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to host arbitrary HTML by abusing bookmark card image fetching. Attackers can create bookmark cards that store non-image files from external websites as icons or thumbnails to compromise other staff users' admin sessions.
Title Ghost 5.94.0 before 6.64.0 Stored XSS via Bookmark Card Images
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-79
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T16:08:58.233Z

Reserved: 2026-10-02T00:44:44.528Z

Link: CVE-2026-104413

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:10.980

Modified: 2026-10-02T16:16:45.050

Link: CVE-2026-104413

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:15:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')