6.8
CVE-2026-105644
- EPSS 0.32%
- Veröffentlicht 05.10.2026 18:53:08
- Zuletzt bearbeitet 06.10.2026 15:17:13
- Erkennungen
Ghost: Stored XSS via SVG Files in Content Imports
Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in content imports were stored without sanitization. An attacker who convinced an Administrator to import a crafted file could host scripts on the site's domain, possibly resulting in compromise of staff users' admin sessions. This issue is fixed in version 6.67.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerTryGhost
≫
Produkt
Ghost
Version
>= 4.0.0, < 6.67.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.229 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.8 | 1.6 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://github.com/TryGhost/Ghost/security/advisories/GHSA-hqq2-xqr2-fmx2
https://github.com/TryGhost/Ghost/pull/31060
https://github.com/TryGhost/Ghost/commit/1be06f4e95a5eb159d14abda7660e689af13cff1
https://github.com/TryGhost/Ghost/releases/tag/v6.66.0