Denial of Service Vulnerability in Ghost CMS by TryGhost
CVE-2026-105646
4.9MEDIUM
What is CVE-2026-105646?
Ghost, a Node.js content management system, is affected by a vulnerability that allows an attacker with Administrator access to exploit crafted content import files. This exploit can result in excessive CPU usage, rendering the Ghost server unresponsive. The issue is resolved in version 6.67.0, encouraging users to upgrade to mitigate potential disruptions.
Affected Version(s)
Ghost >= 4.0.0, < 6.67.0
