Cross-site scripting in Ghost - #VU151104
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary scripts in the Ghost editor, on published sites, and in newsletter emails.
The vulnerability exists due to improper neutralization of input during web page generation in oEmbed photo responses when embedding a URL from an attacker-controlled website. A remote attacker can provide a URL that causes untrusted scripts to be stored in post content to execute arbitrary scripts in the Ghost editor, on published sites, and in newsletter emails.
User interaction is required to render the stored post content.