---
id: CVE-2026-105649
title: Ghost is a Node.js content management system
summary: >-
  Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG
  media thumbnails and SVG images uploaded with a non-SVG file extension were
  stored without sanitization. This allowed any staff user, including
  Contributors, to …
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-79
  - CWE-434
vendor: TryGhost
product: Ghost
affected:
  - 'Ghost >= 4.22.0, < 6.65.0'
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T20:17:13.613'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105649'
references:
  - url: >-
      https://github.com/TryGhost/Ghost/commit/80686226d23df56749f6b7ebb484850a8eba8072
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/issues/30919'
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/releases/tag/v6.65.0'
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-8575-cr6v-7jh4'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T19:30:59.998Z'
---

## Overview

Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.65.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
