CVE-2026-105650: Ghost: Stored XSS via oEmbed Photo Responses
Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting in compromise of a staff user's admin session. This issue is fixed in version 6.64.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.64.0
Event History
Frequently Asked Questions
Which Ghost installations are affected?
Ghost versions from 2.1.0 through 6.64.0 are affected. Version 6.64.0 contains the fix.
What does an attacker need to exploit this issue?
An attacker needs to get a URL from an attacker-controlled website embedded in Ghost content. Exploitation requires a user interaction, as indicated by the UI:R vector.
What is the impact if malicious content is embedded?
Untrusted scripts can be stored in post content and execute in the Ghost editor, on the published site, and in newsletter emails. This could lead to compromise of a staff user's admin session.
How can teams identify potentially affected content?
Review posts containing embedded URLs, particularly those sourced from untrusted or attacker-controlled websites. The vulnerable behavior involves scripts delivered through oEmbed photo responses being stored in post content.