Back

HIGH

Ghost: Stored XSS via Embed Card Previews

Published Oct 5, 2026

Description

Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections against stored cross-site scripting. Any staff user, including Contributors, could store scripts in post content that ran when another staff user opened the post in the editor, potentially compromising that user’s admin session. Self-hosted sites should leave the new  security.embedPreviewUrl  configuration option at its default value. This issue is fixed in version 6.67.0.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (3)
  1. EUVD
    • Updated

      changed from Oct 6, 2026 to Oct 7, 2026

    • Published

      changed from Oct 5, 2026 to Oct 7, 2026

  2. EUVD
    • Updated

      changed from Oct 5, 2026 to Oct 6, 2026

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Oct 5, 2026
Updated Oct 6, 2026
Reserved Oct 5, 2026

CISA Vulnrichment

Updated Oct 6, 2026

NVD

Status Deferred
Modified Oct 6, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Oct 7, 2026
Updated Oct 7, 2026