Cross-site scripting in Ghost - CVE-2026-70596
Published: July 30, 2026 / Updated: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper input validation in feature image captions when rendering crafted post content in Ghost Admin. A remote privileged user can create a post with crafted content to escalate privileges.
User interaction is required for another staff user to view the crafted content.