Impact
Ghost versions 5.94.0 through 6.63.x contain a stored cross‑site scripting vulnerability that allows staff users to host arbitrary HTML by exploiting the bookmark card image fetching logic. Attackers can create bookmark cards that store non‑image files from external websites as icons or thumbnails. When those bookmark cards are rendered by another staff user, the injected HTML is executed within the admin context, potentially giving the attacker access to that session or allowing further manipulation of site data.
Affected Systems
The vulnerability affects TryGhost's Ghost content management system. All installations of Ghost from version 5.94.0 up to but not including 6.64.0 are susceptible. The issue is present in any deployment that allows staff or contributors to create bookmark cards and does not restrict the type of content fetched for bookmark card images.
Risk and Exploitability
The CVSS base score is 8.5, indicating a high severity impact. The EPSS score for this vulnerability is not available, and it is not listed in the CISA KEV catalog. The attack vector is a stored XSS that can be exploited by an attacker who can create or modify bookmark cards, which is generally achievable by any staff or contributor role. Once exploited, the attacker can run arbitrary JavaScript in the context of other staff users’ admin sessions, leading to session hijacking or data tampering. Because the flaw is fully exploitable through normal application usage, the risk to affected deployments is substantial, especially where staff have broad permissions and external image URLs are not sanitized.
OpenCVE Enrichment