Impact
The vulnerability is a Regex Denial of Service that occurs when a crafted content import file is processed by Ghost. The bad input causes catastrophic backtracking in a regular expression, consuming excessive CPU and rendering the server unresponsive for users. The flaw requires the attacker to have Administrator privileges in the Ghost CMS.
Affected Systems
TryGhost Ghost versions from 4.0.0 through 6.67.0 are affected. The issue is fixed starting with version 6.67.0; later releases are not vulnerable. Admin users can trigger the exploit by uploading a malicious import file.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, but the lack of EPSS data and status outside KEV reduces the likelihood of widespread exploitation. Because the attack vector requires elevated privileges, the risk is primarily to organizations with compromised admin accounts or internal attackers. Patching remains the most reliable mitigation.
OpenCVE Enrichment