CVE-2026-105642: Ghost: Remote Code Execution via Bookmark Card Images
Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attacker-controlled website, resulting in arbitrary commands being run on the Ghost server. This issue is fixed in version 6.67.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.67.0
Event History
Frequently Asked Questions
Which Ghost installations are affected?
Ghost versions from 6.56.0 through 6.67.0 are affected. The issue is fixed in version 6.67.0.
Who can exploit this issue?
Any Ghost staff user, including a user with the Contributor role, can exploit it. Exploitation involves creating a bookmark card for an attacker-controlled website.
Does exploitation require direct server access or elevated Ghost permissions?
No. The vulnerability is remotely exploitable and requires no privileges beyond being a Ghost staff user; Contributors are explicitly included.
What is the impact if exploitation succeeds?
Successful exploitation can result in arbitrary commands being executed on the Ghost server, with confidentiality, integrity, and availability all rated high.