Cross-site scripting in Ghost - #VU151948

 

Cross-site scripting in Ghost - #VU151948

Published: September 24, 2026


Vulnerability identifier: #VU151948
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary scripts in other staff users' admin sessions.

The vulnerability exists due to improper neutralization of input during web page generation in Ghost SVG media upload handling when uploading SVG media thumbnails or SVG images with a non-SVG file extension. A remote user can upload a crafted SVG file to execute arbitrary scripts in other staff users' admin sessions.

User interaction is required for the crafted content to be rendered.


Affected software

Ghost

Remediation

Install security update from vendor's website.

Ghost - update to 6.65.0

External References

Related Security Bulletins