CVE-2026-105644: Stored Cross-Site Scripting via Malicious SVG Content Import in Ghost CMS
Vulnerability ID: CVE-2026-105644
CVSS Score: 6.8
Published: 2026-10-07
A Stored Cross-Site Scripting (XSS) and Unrestricted Upload of File with Dangerous Type vulnerability in Ghost CMS (versions 4.0.0 to 6.66.x) allows remote attackers to execute arbitrary JavaScript in the context of an administrator's session. The flaw lies in the content import subsystem, which extracted and stored SVG files without sanitization or binary verification.
TL;DR
Ghost CMS failed to sanitize SVG files included inside bulk content imports (ZIP files). Attackers can trick administrators into importing a malicious ZIP containing crafted SVGs with embedded JavaScript, leading to stored XSS and complete CMS takeover.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-79, CWE-434
- Attack Vector: Network
- CVSS Score: 6.8 (Medium)
- EPSS Score: 0.0032 (0.32%)
- Impact: Stored XSS / Session Hijacking
- Exploit Status: Proof of Concept (PoC)
- KEV Status: Not Listed
Affected Systems
- Ghost Content Management System (CMS)
-
Ghost: >= 4.0.0, < 6.67.0 (Fixed in:
6.67.0)
Code Analysis
Commit: 1be06f4
Add strict SVG validation, sanitizer workflows, magic-byte checking and decoder restrictions inside the image importer handler.
Mitigation Strategies
- Upgrade Ghost CMS platform core to version 6.67.0 or above
- Enforce explicit Content Security Policy (CSP) headers over uploaded resources
- Implement domain-level sandboxing for user-supplied uploaded files
Remediation Steps:
- Navigate to the host system shell hosting Ghost
- Execute command 'ghost update' to pull and install the latest secure package
- Add a strict 'Content-Security-Policy' header rule inside reverse proxy configurations for target image directory endpoints
References
- GHSA-hqq2-xqr2-fmx2 Security Advisory
- Fix Commit
- Pull Request #31060
- Ghost Release Tag v6.66.0
- NVD CVE Entry
Read the full report for CVE-2026-105644 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)