CVE-2026-105642: Remote Code Execution in Ghost CMS via Unsafe SVG Processing during Metadata Scraping
Vulnerability ID: CVE-2026-105642
CVSS Score: 8.8
Published: 2026-10-07
CVE-2026-105642 is a critical remote code execution vulnerability in Ghost CMS, affecting versions 6.56.0 through 6.66.0. The flaw resides in how Ghost's backend handles external image metadata when generating 'Bookmark' cards in the post editor. When a low-privileged staff member inputs a malicious URL, the server fetches and processes an SVG containing an embedded payload, leading to command execution via the underlying, vulnerable image-processing component.
TL;DR
A Remote Code Execution (RCE) flaw in Ghost CMS (versions 6.56.0 - 6.66.0) allows low-privileged users to compromise the host server by inserting a link to an attacker-controlled webpage containing a malicious SVG image.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-94, CWE-1395
- Attack Vector: Network (AV:N)
- CVSS v3.1 Score: 8.8
- EPSS Score: 0.00251
- Exploit Status: poc
- CISA KEV Status: Not Listed
Affected Systems
- Ghost CMS (Self-hosted Node.js instances)
-
Ghost: >= 6.56.0, <= 6.66.0 (Fixed in:
6.67.0)
Code Analysis
Commit: 4cb7e79
Bump package versions and update node configurations for secure sandboxing within the 6.67.0 release
Mitigation Strategies
- Upgrade Ghost CMS to version 6.67.0 or higher.
- Implement outbound firewall rules to block the server from reaching arbitrary external URLs.
- Limit user registration and audit Contributor draft privileges.
Remediation Steps:
- Access the host shell containing the Ghost installation.
- Ensure you are running the latest version of the Ghost-CLI tool by running 'npm install -g ghost-cli@latest'.
- Execute the upgrade sequence inside the active Ghost directory using 'ghost update'.
- Verify that the active Ghost version is 6.67.0 or newer by running 'ghost version'.
References
- GitHub Security Advisory GHSA-788w-68h3-cvxp
- NVD - CVE-2026-105642
- CVE.org Record
- Ghost Version Release Commit
Read the full report for CVE-2026-105642 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)