{"id":"CVE-2026-105644","title":"Ghost is a Node.js content management system","summary":"Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in content imports were stored without sanitization. An attacker who convinced an Administrator to import a crafted file could host scripts on the…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","cwe":["CWE-79","CWE-434"],"vendor":"TryGhost","product":"Ghost","affected":["Ghost >= 4.0.0, < 6.67.0"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T19:17:19.060","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105644","references":[{"url":"https://github.com/TryGhost/Ghost/commit/1be06f4e95a5eb159d14abda7660e689af13cff1","label":"security-advisories@github.com"},{"url":"https://github.com/TryGhost/Ghost/pull/31060","label":"security-advisories@github.com"},{"url":"https://github.com/TryGhost/Ghost/releases/tag/v6.66.0","label":"security-advisories@github.com"},{"url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-hqq2-xqr2-fmx2","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-05T19:30:59.980Z","slug":"CVE-2026-105644","body":"## Overview\n\nGhost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in content imports were stored without sanitization. An attacker who convinced an Administrator to import a crafted file could host scripts on the site's domain, possibly resulting in compromise of staff users' admin sessions. This issue is fixed in version 6.67.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}