Cross-site scripting in Ghost - CVE-2026-70588
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to inject arbitrary script code into post content.
The vulnerability exists due to improper neutralization of input during web page generation in the Universal Import feature in Ghost Admin when importing content. A remote privileged user can import specially crafted content to inject arbitrary script code into post content.