Cross-site scripting in Ghost - #VU151948
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary scripts in other staff users' admin sessions.
The vulnerability exists due to improper neutralization of input during web page generation in Ghost SVG media upload handling when uploading SVG media thumbnails or SVG images with a non-SVG file extension. A remote user can upload a crafted SVG file to execute arbitrary scripts in other staff users' admin sessions.
User interaction is required for the crafted content to be rendered.