CVE-2026-105651: Ghost: Stored XSS via Bookmark Card Images
Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from an external website as bookmark icons or thumbnails. This allowed any staff user, including Contributors, to host arbitrary HTML on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.64.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.64.0
Event History
Frequently Asked Questions
Which Ghost deployments are affected?
Ghost versions from 5.94.0 up to, but not including, 6.64.0 are affected. The issue is fixed in Ghost 6.64.0.
What access does an attacker need to exploit this issue?
An attacker needs a staff account. Contributors are included, so exploitation does not require administrator-level privileges.
How could this affect other users?
A staff user could cause arbitrary HTML fetched from an external website to be stored on the Ghost site's domain as a bookmark icon or thumbnail. This could enable stored cross-site scripting and potentially compromise other staff users' admin sessions.
Are sites affected by default?
The vulnerable behavior is triggered when creating a bookmark card and using externally fetched content for its icon or thumbnail. The provided information does not indicate any additional configuration requirement.