Cross-site scripting in Ghost - CVE-2026-70588

 

Cross-site scripting in Ghost - CVE-2026-70588

Published: July 30, 2026


Vulnerability identifier: #VU140546
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-70588
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject arbitrary script code into post content.

The vulnerability exists due to improper neutralization of input during web page generation in the Universal Import feature in Ghost Admin when importing content. A remote privileged user can import specially crafted content to inject arbitrary script code into post content.


Affected software

Ghost

How to mitigate CVE-2026-70588

Install security update from vendor's website.

Ghost - update to 6.54.1

External References

Related Security Bulletins