Improper isolation or compartmentalization in Ghost - #VU142540
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute untrusted script in a staff user\'s admin session.
The vulnerability exists due to improper isolation or compartmentalization in the oEmbed preview in the Ghost editor when rendering externally hosted scripts. A remote attacker can supply crafted embedded content to execute untrusted script in a staff user\'s admin session.
User interaction is required when a staff user views the crafted oEmbed preview.