Node.js Content Management System Vulnerability in Ghost by TryGhost
CVE-2026-105651
7.3HIGH
What is CVE-2026-105651?
A security flaw in Ghost, a Node.js based content management system, allows users with staff privileges, including Contributors, to upload non-image files as bookmark icons or thumbnails. This exploit can lead to arbitrary HTML being executed on the site’s domain, potentially compromising the admin sessions of fellow staff users. The issue has been resolved in version 6.64.0, emphasizing the importance of updating to the latest version to mitigate risks.
Affected Version(s)
Ghost >= 5.94.0, < 6.64.0
