Description
Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections against stored cross-site scripting. Any staff user, including Contributors, could store scripts in post content that ran when another staff user opened the post in the editor, potentially compromising that user’s admin session. Self-hosted sites should leave the new  security.embedPreviewUrl  configuration option at its default value. This issue is fixed in version 6.67.0.
Published: 2026-10-05
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution via Stored XSS that can compromise staff admin sessions
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows a staff user, including Contributors, to embed malicious scripts within post content using Ghost’s editor. The scripts are stored and then executed automatically when another staff member opens the post in the editor, effectively turning the content into a cross‑site scripting payload that runs with the privileges of the staff user. The weakness corresponds to CWE‑79 (Cross‑Site Scripting) and CWE‑653 (Perceived Information Disclosure). An attacker can thus alter the context of a staff session, steal cookies, or perform actions as the staff user.

Affected Systems

TryGhost Ghost, a Node.js content management system, is vulnerable in versions 6.34.0 through 6.67.0. The issue applies to self‑hosted installations; the new configuration option security.embedPreviewUrl must remain at its default value to preserve security posture.

Risk and Exploitability

The CVSS score of 7.3 indicates high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The attack requires the attacker to have staff or Contributor access to create or edit posts, and the exploit succeeds only when another staff user opens the post, making the threat primarily internal. Nevertheless, if internal users are compromised, the attacker can elevate privileges within the Ghost environment. The vulnerability is mitigated by upgrading to version 6.67.0 or later and ensuring the security.embedPreviewUrl setting is left at its default value.

Generated by OpenCVE AI on October 5, 2026 at 20:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.67.0 or newer to apply the vendor fix
  • Verify that the configuration option security.embedPreviewUrl remains at its default value
  • Remove any stored embed cards that contain malicious scripts and review current contributors for appropriate role permissions

Generated by OpenCVE AI on October 5, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections against stored cross-site scripting. Any staff user, including Contributors, could store scripts in post content that ran when another staff user opened the post in the editor, potentially compromising that user’s admin session. Self-hosted sites should leave the new  security.embedPreviewUrl  configuration option at its default value. This issue is fixed in version 6.67.0.
Title Ghost: Stored XSS via Embed Card Previews
Weaknesses CWE-653
CWE-79
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T18:48:31.778Z

Reserved: 2026-10-05T16:40:39.612Z

Link: CVE-2026-105643

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T19:17:18.900

Modified: 2026-10-05T19:17:18.900

Link: CVE-2026-105643

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T20:30:22Z

Weaknesses
  • CWE-653

    Improper Isolation or Compartmentalization

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')