SVG Handling Vulnerability in Ghost Node.js CMS
CVE-2026-105642
8.8HIGH
What is CVE-2026-105642?
A vulnerability in the image processing library of the Ghost Node.js content management system versions 6.56.0 to 6.67.0 allows staff users, including Contributors, to create bookmark cards for attacker-controlled websites. This leads to the potential execution of arbitrary commands on the Ghost server, posing a significant security risk. The vulnerability has been addressed in version 6.67.0.
Affected Version(s)
Ghost >= 6.56.0, < 6.67.0
