Impact
Ghost, a Node.js content management system, is vulnerable to a regular expression denial of service through its external media inliner. A crafted request can cause the server to consume excessive CPU, rendering the web application unresponsive. The flaw is classified as CWE‑1333, indicating that a single client can trigger a computationally expensive regular expression that exhausts system resources.
Affected Systems
The vulnerability affects Ghost versions from 5.37.0 through 6.66.x inclusive. All installations running any of these releases must be checked. Exploitation requires an administrator account to send the specially crafted request, so only users with elevated privileges can activate the denial of service.
Risk and Exploitability
The CVSS score is 4.9, placing the issue in the medium severity range. EPSS data is currently unavailable and the vulnerability is not listed in the CISA KEV catalog, implying no known public exploitation yet. Nevertheless, because the attack requires admin access, an attacker who acquires such privileges can force the Ghost server into a state of resource exhaustion and loss of availability.
OpenCVE Enrichment