CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-105645

CVE-2026-105645: Regular Expression Denial of Service (ReDoS) in Ghost CMS

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 8, 2026·6 min read·4 visits

Executive Summary (TL;DR)

An authenticated administrator can cause a permanent Denial of Service (DoS) of the Ghost CMS server by uploading a crafted ZIP containing recursive/nested directory patterns or triggering malicious wildcard domain matching in the external media inliner, freezing the single-threaded Node.js event loop.

CVE-2026-105645 is a regular expression denial of service (ReDoS) vulnerability affecting Ghost, an open-source Node.js content management system. The vulnerability exists within directory import handlers and the external media inliner, allowing authenticated administrators to trigger catastrophic backtracking in the V8 JavaScript engine, resulting in infinite loops, 100% CPU utilization, and total denial of service.

Vulnerability Overview

The vulnerability identified as CVE-2026-105645 (GHSA-9m4w-fmjw-fvjq) represents a medium-severity Regular Expression Denial of Service (ReDoS) flaw in the core architecture of Ghost, a widely-deployed open-source Node.js Content Management System (CMS). The defect manifests in two distinct functional modules: the directory import subsystem (responsible for parsing content archives) and the External Media Inliner service (designed to retrieve external media during database migrations).

An authenticated attacker with administrative privileges can exploit this weakness by submitting input patterns specifically crafted to induce catastrophic backtracking in the V8 JavaScript regular expression engine. Because Node.js is built on a single-threaded execution model, a CPU-bound operation like regular expression backtracking blocks the entire event loop, preventing the server from processing any subsequent incoming HTTP requests.

The impact is confined to application availability, resulting in a complete denial of service for the target instance. The issue affects Ghost versions ranging from 5.37.0 up to (but not including) 6.67.0. Mitigation involves updating to version 6.67.0, which introduces comprehensive input escaping for import pathways and enforces execution time limits via a separate virtual machine context for wildcard domain matching.

Technical Root Cause Analysis

The fundamental cause of the vulnerability lies in the use of user-controlled inputs during the dynamic compilation of regular expressions. Within the import handlers, Ghost dynamically constructs regular expressions to normalize archive directory layouts and match static file prefixes using path-derived variables such as baseDir and startDir. When constructing these regular expressions, the engine did not escape or validate literal directory paths before appending them directly into the regular expression constructor.

If an administrator uploads an archive where a folder name contains regex metacharacters with nested quantifiers, such as (a+)+b, the variable is evaluated directly. This causes the regular expression parser to interpret the path as an active pattern rather than a literal string. When matching a filename like aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaac.jpg against /^(a+)+b//, the engine evaluates exponential combinations of the character group before encountering the non-matching character at the end, leading to catastrophic backtracking.

In the External Media Inliner service, the root cause is slightly different but yields the same system-level outcome. The service parses post contents to discover and download media from external wildcards. Because these external domains contain intentional wildcards (e.g., https?://i[0-9]{1}.wp.com), escaping is not viable. The combined regular expression built to locate matches is evaluated synchronously without any execution time bounds. An attacker-controlled wildcard domain containing nested groupings evaluated against long, repetitive structures inside post contents can indefinitely starve the event loop.

Code Analysis & Patch Verification

An examination of the fix commit (88ae6d6d56f8a239cb38a8c89de02f034f50e2ce) reveals a two-pronged remediation strategy designed by the maintainers. For the directory import handlers, the dynamic path compilation is secured by integrating lodash's escaping library. By wrapping the variable parameters inside _.escapeRegExp(), all metacharacters are safely escaped, ensuring that V8 evaluates folder structures purely as literal sequences of characters.

In contrast, the External Media Inliner requires wildcard evaluation to perform its core tasks. Because escaping would destroy the wildcard functionality, the developers utilized the Node.js node:vm standard library module. This module permits executing JavaScript scripts within an isolated V8 context under strict performance criteria.

// A snippet illustrating the sandbox matching model introduced in the patch
const vm = require('node:vm');
const FIND_MATCHES_TIMEOUT_MS = 1000;
 
let findMatchesScript;
let findMatchesContext;
 
function matchAllWithTimeout(content, regex, timeout) {
  if (!findMatchesScript) {
    findMatchesScript = new vm.Script('Array.from(content.matchAll(regex), (match) => match[1])');
    findMatchesContext = vm.createContext({});
  }
  findMatchesContext.content = content;
  findMatchesContext.regex = regex;
  try {
    return Array.from(findMatchesScript.runInContext(findMatchesContext, { timeout }));
  } finally {
    findMatchesContext.content = undefined;
    findMatchesContext.regex = undefined;
  }
}

By executing the regex search within a sandbox with a timeout of 1000 milliseconds, the engine guarantees that any search requiring intensive backtracking is terminated. When the timeout threshold is breached, the runtime throws an ERR_SCRIPT_EXECUTION_TIMEOUT exception, which is caught and handled gracefully by logging the failure and continuing processing. This ensures the single-threaded event loop is freed up for pending networking tasks.

Exploitation Methodology

Exploitation requires administrative-level authentication to target either the directory import system or the media inliner configuration settings. An attacker begins by packaging a ZIP archive that mirrors the structure of an image or content import. The attacker names one of the directories within the archive (a+)+b. Inside this directory, the attacker places a file named aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaac.jpg.

Upon uploading this file via the Ghost admin control panel, the application invokes the loadFile() method inside the ImporterContentFileHandler or ImageHandler modules. The server extracts the archive, retrieves the path string, and initiates the dynamic compilation step: const baseDirRegex = new RegExp('^' + baseDir + '/'). The resulting regular expression /^(a+)+b// is then matched against the long name of the nested file. This starts the catastrophic backtracking process, forcing the CPU core hosting the Ghost instance to 100% capacity and preventing incoming connection responses.

Alternatively, the attacker can leverage the External Media Inliner. The attacker registers or specifies a domain pattern containing nested-backtracking sequences, such as (a+)+b. By subsequently creating or importing post content that contains a lengthy, repetitive sequence of characters that lacks the terminating character (such as 40 characters of 'a' followed by a 'c'), the attacker triggers the processing queue. When inlineContent() executes, the synchronous call to findMatches() matches the malicious content against the vulnerable domain pattern, stalling the entire application.

Severity & Impact Evaluation

This vulnerability has been assigned a CVSS v3.1 base score of 4.9 (Medium), with a vector of CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H. The assessment reflects a high impact on availability, balanced by the requirement for administrative privileges (PR:H). Because administrative access is necessary to initiate ZIP imports or configure external media services, the likelihood of drive-by remote exploitation is minimal.

The consequence of a successful exploitation is a complete Denial of Service (DoS) of the Node.js application process. In single-instance deployments lacking auto-restarts or process monitoring, the server remains in a hung state indefinitely. In containerized environments managed by orchestrators like Kubernetes, the container may eventually trigger a liveness probe failure and restart, but repeated exploitation attempts can lead to a continuous crash-loop state, rendering the platform permanently unavailable.

Furthermore, because the synchronous timeout inside the patched version of the media inliner is capped at 1000 milliseconds, a sequence of multiple crafted payloads can still induce a temporary event loop lag. Although the immediate risk of infinite freezing is mitigated by the VM sandbox, administrators must remain vigilant against potential exploitation windows that could slow down legitimate HTTP traffic.

Official Patches

TryGhostOfficial Ghost Security Advisory for CVE-2026-105645

Fix Analysis (1)

Technical Appendix

CVSS Score
4.9/ 10
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
EPSS Probability
0.33%
Top 76% most exploited

Affected Systems

TryGhost/Ghost CMS deployment environments

Affected Versions Detail

Product
Affected Versions
Fixed Version
Ghost
TryGhost
>= 5.37.0, < 6.67.06.67.0
AttributeDetail
CWE IDCWE-1333
Attack VectorNetwork
CVSS v3.1 Score4.9 (Medium)
EPSS Score0.00327 (Percentile: 23.71%)
ImpactDenial of Service (Availability)
Exploit StatusProof of Concept (PoC)
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1499.004Endpoint Denial of Service: Application Exhaustion Flood
Impact
CWE-1333
Inefficient Regular Expression Complexity

The application uses a regular expression with an inefficient evaluation complexity that can be exploited to consume excessive CPU resources.

Known Exploits & Detection

GitHubRegression test suite proving catastrophic backtracking paths in importer-content-file-handler and external-media-inliner.

Vulnerability Timeline

Vulnerability remediation patch committed to official repository
2026-09-28
Release branch version tagging is processed
2026-09-29
Security Advisory GHSA-9m4w-fmjw-fvjq published on GitHub
2026-10-05
CVE-2026-105645 published in National Vulnerability Database (NVD)
2026-10-05

References & Sources

  • [1]GitHub Security Advisory GHSA-9m4w-fmjw-fvjq
  • [2]Official Patch Commit
  • [3]Ghost Release Tag v6.66.0
  • [4]Vulnerability Tracking Issue

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•19 minutes ago•CVE-2026-105646
4.9

CVE-2026-105646: Regular Expression Denial of Service in Ghost CMS Import Handlers

An authenticated Regular Expression Denial of Service (ReDoS) vulnerability in TryGhost Ghost (CMS) versions 4.0.0 through 6.66.x. An attacker with administrator privileges can upload crafted content import archives containing pathological directory names or migration patterns, triggering exponential backtracking in the Node.js V8 engine.

Alon Barad
Alon Barad
2 views•6 min read
•about 2 hours ago•CVE-2026-105644
6.8

CVE-2026-105644: Stored Cross-Site Scripting via Malicious SVG Content Import in Ghost CMS

A Stored Cross-Site Scripting (XSS) and Unrestricted Upload of File with Dangerous Type vulnerability in Ghost CMS (versions 4.0.0 to 6.66.x) allows remote attackers to execute arbitrary JavaScript in the context of an administrator's session. The flaw lies in the content import subsystem, which extracted and stored SVG files without sanitization or binary verification.

Amit Schendel
Amit Schendel
5 views•6 min read
•about 3 hours ago•CVE-2026-105643
7.3

CVE-2026-105643: Stored Cross-Site Scripting and Isolation Bypass in Ghost CMS

Stored Cross-Site Scripting (XSS) and origin isolation bypass vulnerability in Ghost CMS versions 6.34.0 through 6.66.1 allows low-privileged staff users to execute arbitrary JavaScript in the context of an administrator session via crafted embed cards.

Alon Barad
Alon Barad
7 views•6 min read
•about 4 hours ago•CVE-2026-105642
8.8

CVE-2026-105642: Remote Code Execution in Ghost CMS via Unsafe SVG Processing during Metadata Scraping

CVE-2026-105642 is a critical remote code execution vulnerability in Ghost CMS, affecting versions 6.56.0 through 6.66.0. The flaw resides in how Ghost's backend handles external image metadata when generating 'Bookmark' cards in the post editor. When a low-privileged staff member inputs a malicious URL, the server fetches and processes an SVG containing an embedded payload, leading to command execution via the underlying, vulnerable image-processing component.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 5 hours ago•CVE-2026-61439
7.5

CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense Engine

This report provides a comprehensive technical analysis of CVE-2026-61439 (GHSA-fj8f-m44g-c479), a prompt injection defense bypass vulnerability in the PraisonAI multi-agent framework. In versions prior to 4.6.78, the InjectionDefense scanner threshold defaulted to CRITICAL. This allowed single-vector prompt injections classified as HIGH severity (e.g., direct instruction overrides or financial manipulations) to pass through unblocked, enabling attackers to extract system prompts and execute unauthorized agent tools.

Alon Barad
Alon Barad
5 views•7 min read
•about 6 hours ago•CVE-2026-104890
7.2

CVE-2026-104890: Remote Code Execution via Mixed-Case File Upload Bypass in Kunstmaan CMS MediaBundle

Kunstmaan CMS MediaBundle prior to version 7.3.2 contains a critical file upload vulnerability where case-sensitive extension checks can be bypassed using mixed-case file extensions. Because extension normalization occurs after the validation routine, files with mixed-case executable extensions (such as pHp) bypass checks but are stored with normalized lowercase executable extensions, allowing authenticated administrators to achieve remote code execution.

Amit Schendel
Amit Schendel
12 views•6 min read