CVE-2026-103277
8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Summary
Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in the context of a staff user's admin session, potentially compromising administrative access.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TryGhost | Ghost | 2.5.0 < 6.34.0 | affected |
| TryGhost | Ghost | 6.34.0 | unaffected |
Weaknesses
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-8vhf-xxpj-4qrg
- https://www.vulncheck.com/advisories/ghost-2.5.0-before-6.34.0-untrusted-script-execution-via-oembed
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.