CVE-2026-105649: Ghost: Stored XSS via SVG Uploads Bypassing Sanitization
Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.65.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.65.0
Event History
Frequently Asked Questions
Which deployments are affected?
Ghost versions from 4.22.0 through 6.65.0 are affected. The issue is fixed in version 6.65.0.
What level of access does an attacker need?
An attacker needs a staff account with the ability to upload media. This includes the Contributor role.
What is the likely impact of successful exploitation?
A staff user can upload a crafted SVG that hosts scripts on the site's domain. Those scripts could compromise the admin sessions of other staff users who interact with the malicious content.