Description
Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in content imports were stored without sanitization. An attacker who convinced an Administrator to import a crafted file could host scripts on the site's domain, possibly resulting in compromise of staff users' admin sessions. This issue is fixed in version 6.67.0.
Published: 2026-10-05
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Stored XSS enabling attacker to compromise administrator sessions
Action: Immediate Patch
AI Analysis

Impact

Ghost CMS versions from 4.0.0 through 6.67.0 improperly store SVG images during content import without sanitization. When an attacker tricks an administrator into importing a crafted SVG file, the malicious code is embedded in the page content and subsequently executed in the context of any user who views that content, notably staff users with administrative privileges. This form of stored cross‑site scripting can allow the attacker to steal session tokens, bypass authentication, or perform further privileged actions on the site.

Affected Systems

The impact applies to installations of TryGhost Ghost CMS with content import functionality enabled, specifically versions 4.0.0 to 6.67.0 inclusive. Any deployment that permits SVG uploads in content imports during those release periods is affected.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity, and while EPSS data is unavailable, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires social engineering to persuade an administrator to import the malicious file; once imported, the payload the next time an administrator accesses the affected content can gain control of the admin session. Although not a remote code execution flaw, the potential to hijack privileged sessions raises the risk level above typical low‑impact XSS scenarios.

Generated by OpenCVE AI on October 5, 2026 at 20:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.67.0 or later
  • Disable or restrict SVG uploads in content imports until proper sanitization is implemented
  • Audit the content import code path to ensure all SVG inputs are sanitized or removed before storage

Generated by OpenCVE AI on October 5, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in content imports were stored without sanitization. An attacker who convinced an Administrator to import a crafted file could host scripts on the site's domain, possibly resulting in compromise of staff users' admin sessions. This issue is fixed in version 6.67.0.
Title Ghost: Stored XSS via SVG Files in Content Imports
Weaknesses CWE-434
CWE-79
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T18:53:08.624Z

Reserved: 2026-10-05T16:40:39.612Z

Link: CVE-2026-105644

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T19:17:19.060

Modified: 2026-10-05T19:17:19.060

Link: CVE-2026-105644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T20:30:22Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')