Node.js Content Management System Vulnerability in Ghost by TryGhost
CVE-2026-105650

8.1HIGH

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105650?

Ghost, a popular Node.js-based content management system, has a vulnerability that allows scripts from attacker-controlled URLs to be embedded within post content. This can lead to unvalidated scripts running not just in the Ghost editor but also on the published site and in newsletter emails, posing a risk to the security of staff users' admin sessions. The issue has been addressed in version 6.64.0, ensuring that such vulnerabilities do not compromise the integrity of websites powered by Ghost.

Affected Version(s)

Ghost >= 2.5.0, < 6.64.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.