Untrusted Script Execution in Ghost from 2.5.0 up to 6.34.0
CVE-2026-103277

8.6HIGH

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103277?

Ghost versions from 2.5.0 through 6.34.0 are affected by an untrusted script execution vulnerability in the oEmbed preview feature. This flaw allows attackers to create malicious oEmbed content that can execute scripts within the context of an administrative user’s session. If exploited, this vulnerability could lead to unauthorized administrative access, potentially jeopardizing the integrity of the affected systems.

Affected Version(s)

Ghost 2.5.0 < 6.34.0

Ghost 6.34.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.