HIGH
Ghost: Stored XSS via oEmbed Photo Responses
Published Oct 5, 2026
8.1
HIGHCVSS 3.1
EPSS 0.33%
Description
Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting in compromise of a staff user's admin session. This issue is fixed in version 6.64.0.
Affected products
-
Affected
- ≥ 2.5.0, < 6.64.0
No data.
No data.
No Red Hat product state for this CVE.
ghost
npm
Introduced 2.5.0 Fixed 6.64.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | ghost | 2.5.0 | 6.64.0 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-92760 Advisory
- https://github.com/TryGhost/Ghost/commit/d23d552e257e2696c60293bc5cd7898a49d6bd1f x_refsource_MISC
- https://github.com/TryGhost/Ghost/pull/30763 x_refsource_MISC
- https://github.com/TryGhost/Ghost/releases/tag/v6.64.0 x_refsource_MISC
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-v3xr-g6p2-fvgv x_refsource_CONFIRM
- https://github.com/advisories/GHSA-v3xr-g6p2-fvgv Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-105650
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-92760 | Advisory | |
| https://github.com/TryGhost/Ghost/commit/d23d552e257e2696c60293bc5cd7898a49d6bd1f | x_refsource_MISC | |
| https://github.com/TryGhost/Ghost/pull/30763 | x_refsource_MISC | |
| https://github.com/TryGhost/Ghost/releases/tag/v6.64.0 | x_refsource_MISC | |
| https://github.com/TryGhost/Ghost/security/advisories/GHSA-v3xr-g6p2-fvgv | x_refsource_CONFIRM | |
| https://github.com/advisories/GHSA-v3xr-g6p2-fvgv | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-105650 |
Change history (4)
- EUVD
Updated
changed from Oct 7, 2026 to Oct 6, 2026Oct 7, 2026 → Oct 6, 2026
Published
changed from Oct 7, 2026 to Oct 5, 2026Oct 7, 2026 → Oct 5, 2026
- EUVD
Updated
changed from Oct 6, 2026 to Oct 7, 2026Oct 6, 2026 → Oct 7, 2026
Published
changed from Oct 5, 2026 to Oct 7, 2026Oct 5, 2026 → Oct 7, 2026
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 5, 2026
Updated Oct 6, 2026
Reserved Oct 5, 2026
Link CVE-2026-105650
CISA Vulnrichment
Updated Oct 6, 2026
Red Hat
No data
GitHub
Link GHSA-V3XR-G6P2-FVGV