SVG Image Handling Vulnerability in Ghost Node.js Content Management System
CVE-2026-105644

6.8MEDIUM

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105644?

The vulnerability in the Ghost CMS arises from the improper handling of SVG images included in content imports from versions 4.0.0 to 6.67.0. Unsanitized SVG files can potentially host malicious scripts that, if executed, might allow attackers to compromise administrator sessions on the site. The flaw enables attackers to craft specific files that, when imported by an administrator, could result in a precarious security landscape. This issue was addressed with the release of version 6.67.0, which implements necessary sanitization measures for SVG images, reinforcing the security posture of sites utilizing the Ghost platform.

Affected Version(s)

Ghost >= 4.0.0, < 6.67.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.