---
id: CVE-2026-70588
title: Ghost is a Node.js content management system
summary: >-
  Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the
  Universal Import feature in Ghost Admin failed to properly sanitize imported
  content resulting in XSS in post content. This issue is fixed in version
  6.54.1.
severity: medium
cvss: 5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:L'
cwe:
  - CWE-79
vendor: ghost
product: ghost
affected:
  - 'ghost >= 5.26.0, < 6.54.1'
patched:
  - ghost 6.54.1
published: '2026-08-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:51:43.490'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-70588'
references:
  - url: >-
      https://github.com/TryGhost/Ghost/commit/a8bea3a4ceec4c852b880f4885119453c3d8588e
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/pull/29635'
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/releases/tag/v6.54.1'
    label: security-advisories@github.com
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-2gx6-7gx2-wwcf'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-2gx6-7gx2-wwcf'
tags:
  - nvd
  - ghsa
  - npm
epss: 0.00258
epssPercentile: 0.17778
aliases:
  - GHSA-2gx6-7gx2-wwcf
ecosystem: npm
ingestedAt: '2026-08-04T21:42:19.549Z'
---

## Overview

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-70588)

Affected packages:

- `ghost >= 5.26.0, < 6.54.1`

Patched in:

- `ghost 6.54.1`

Source: https://github.com/advisories/GHSA-2gx6-7gx2-wwcf
