CVE-2026-104414: Ghost from 2.5.0 before 6.64.0 Stored XSS via oEmbed Photo Responses
Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embedding their URL stores scripts that run in the Ghost editor, published site, and newsletter emails, compromising staff admin sessions.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Ghost versions from 2.5.0 up to, but not including, 6.64.0 are affected. The issue involves content that embeds a URL whose oEmbed photo response is controlled by an attacker.
What does an attacker need to exploit this issue?
An attacker needs to host a malicious oEmbed photo response and have its URL embedded into Ghost post content. No attacker privileges are stated, but a user must interact with the malicious embedded content for the script to run.
Where can the injected script execute?
The stored script can execute in the Ghost editor, on the published site, and in newsletter emails. The described impact includes compromise of staff administrator sessions.