Impact
This vulnerability allows a staff user, including Contributors, to embed malicious scripts within post content using Ghost’s editor. The scripts are stored and then executed automatically when another staff member opens the post in the editor, effectively turning the content into a cross‑site scripting payload that runs with the privileges of the staff user. The weakness corresponds to CWE‑79 (Cross‑Site Scripting) and CWE‑653 (Perceived Information Disclosure). An attacker can thus alter the context of a staff session, steal cookies, or perform actions as the staff user.
Affected Systems
TryGhost Ghost, a Node.js content management system, is vulnerable in versions 6.34.0 through 6.67.0. The issue applies to self‑hosted installations; the new configuration option security.embedPreviewUrl must remain at its default value to preserve security posture.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The attack requires the attacker to have staff or Contributor access to create or edit posts, and the exploit succeeds only when another staff user opens the post, making the threat primarily internal. Nevertheless, if internal users are compromised, the attacker can elevate privileges within the Ghost environment. The vulnerability is mitigated by upgrading to version 6.67.0 or later and ensuring the security.embedPreviewUrl setting is left at its default value.
OpenCVE Enrichment