CVE-2026-105642High· 8.8▾ TwilightGhost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card fo…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attacker-controlled website, resulting in arbitrary commands being run on the Ghost server. This issue is fixed in version 6.67.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105677High· 7.2Ghost is a Node.js content management system
CVE-2026-105682Low· 2.7Ghost is a Node.js content management system
CVE-2026-105683Low· 3.8Ghost is a Node.js content management system
CVE-2026-105679High· 7.3Ghost is a Node.js content management system
CVE-2026-105680Medium· 6.5Ghost is a Node.js content management system
CVE-2026-105681Medium· 6.5Ghost is a Node.js content management system