Cross-site scripting in Ghost - #VU151103

 

Cross-site scripting in Ghost - #VU151103

Published: September 18, 2026


Vulnerability identifier: #VU151103
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise other staff users' admin sessions.

The vulnerability exists due to improper neutralization of input during web page generation in bookmark card images when creating bookmark cards that fetch externally hosted non-image files. A remote user can create a bookmark card that stores an arbitrary HTML file as an icon or thumbnail to compromise other staff users' admin sessions.

User interaction is required.


Affected software

Ghost

Remediation

Install security update from vendor's website.

Ghost - update to 6.64.0

External References

Related Security Bulletins