Back

HIGH

Ghost: Stored XSS via oEmbed Photo Responses

Published Oct 5, 2026

Description

Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting in compromise of a staff user's admin session. This issue is fixed in version 6.64.0.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (4)
  1. EUVD
    • Updated

      changed from Oct 7, 2026 to Oct 6, 2026

    • Published

      changed from Oct 7, 2026 to Oct 5, 2026

  2. EUVD
    • Updated

      changed from Oct 6, 2026 to Oct 7, 2026

    • Published

      changed from Oct 5, 2026 to Oct 7, 2026

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Oct 5, 2026
Updated Oct 6, 2026
Reserved Oct 5, 2026

CISA Vulnrichment

Updated Oct 6, 2026

NVD

Status Deferred
Modified Oct 6, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Oct 5, 2026
Updated Oct 6, 2026