Cross-site scripting in Ghost - #VU151104

 

Cross-site scripting in Ghost - #VU151104

Published: September 18, 2026


Vulnerability identifier: #VU151104
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary scripts in the Ghost editor, on published sites, and in newsletter emails.

The vulnerability exists due to improper neutralization of input during web page generation in oEmbed photo responses when embedding a URL from an attacker-controlled website. A remote attacker can provide a URL that causes untrusted scripts to be stored in post content to execute arbitrary scripts in the Ghost editor, on published sites, and in newsletter emails.

User interaction is required to render the stored post content.


Affected software

Ghost

Remediation

Install security update from vendor's website.

Ghost - update to 6.64.0

External References

Related Security Bulletins