---
id: CVE-2026-103277
title: >-
  Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution
  vulnerability in the oEmbed preview feature that fails to sandbox externally
  hosted scripts
summary: >-
  Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution
  vulnerability in the oEmbed preview feature that fails to sandbox externally
  hosted scripts. Attackers can craft malicious oEmbed content to execute
  scripts in…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-79
vendor: TryGhost
product: Ghost
affected:
  - Ghost >= 2.5.0 < 6.34.0
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T11:17:23.403'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103277'
references:
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-8vhf-xxpj-4qrg'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ghost-2.5.0-before-6.34.0-untrusted-script-execution-via-oembed
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T11:42:53.810Z'
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-01T13:34:51.106508Z'
---

## Overview

Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in the context of a staff user's admin session, potentially compromising administrative access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
