CVE-2026-105643 Overview
CVE-2026-105643 is a stored cross-site scripting (XSS) vulnerability in Ghost, a Node.js content management system. The flaw affects Ghost versions 6.34.0 through 6.66.x and allows any staff user, including Contributors, to store malicious scripts in post content through embed cards in the Ghost editor. The scripts execute when another staff user opens the affected post in the editor, enabling the compromise of higher-privileged admin sessions. Ghost version 6.67.0 resolves the issue. The vulnerability is tracked under CWE-79 (Improper Neutralization of Input During Web Page Generation).
Critical Impact
A low-privileged Contributor can hijack an administrator's authenticated session by planting JavaScript inside a draft post that executes when an admin reviews the content.
Affected Products
- Ghost (Node.js CMS) version 6.34.0
- Ghost versions 6.35.0 through 6.66.x
- Self-hosted Ghost deployments without the default security.embedPreviewUrl configuration
Discovery Timeline
- 2026-10-05 - CVE-2026-105643 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-105643
Vulnerability Analysis
Ghost's editor renders embed cards that fetch and display third-party content such as videos, tweets, and iframes. The embed card feature failed to adequately sanitize or isolate rendered content before the editor loaded it in the admin interface. An attacker with Contributor-level access could craft an embed payload containing JavaScript that persisted in the post record. When another staff user opened that post in the editor, the browser executed the attacker-controlled script within the Ghost admin origin.
Because the payload runs inside an authenticated admin session, the attacker can issue administrative API calls, create new owner accounts, exfiltrate content, or modify site settings. This privilege escalation path turns the weakest staff role into a route for complete site takeover.
Root Cause
The vulnerability stems from insufficient output encoding and sandboxing of embed card previews rendered inside the Ghost editor. User-supplied embed URLs and markup were trusted when rendered in the privileged admin context, bypassing the content security protections applied to published post HTML.
Attack Vector
Exploitation requires an authenticated staff account with post-authoring permission and relies on a second staff user interacting with the malicious draft. The attacker creates or edits a post, inserts an embed card referencing attacker-controlled markup, and saves the draft. When an Editor, Administrator, or Owner subsequently opens the post in the editor, the stored script executes with that user's privileges. Refer to the Ghost security advisory GHSA-69qc-f5m6-889c for additional detail on the affected code paths.
Detection Methods for CVE-2026-105643
Indicators of Compromise
- Posts or drafts containing embed cards with unexpected <script> tags, inline event handlers, or javascript: URLs in the mobiledoc or lexical content fields.
- Admin API requests originating from staff user sessions that create new users, change roles, or modify integration keys without a corresponding audit trail of user action.
- Outbound requests from staff browsers to unknown domains immediately after opening a specific post in the editor.
Detection Strategies
- Audit stored post content for embed cards referencing non-approved domains or containing raw HTML with scriptable attributes.
- Review Ghost admin access logs for privilege changes, API key generation, or new staff invitations initiated shortly after draft reviews.
- Correlate editor page loads with anomalous admin API calls from the same session to identify script-driven activity.
Monitoring Recommendations
- Enable detailed audit logging for Ghost admin actions and forward logs to a centralized SIEM for retention and correlation.
- Monitor the security.embedPreviewUrl configuration on self-hosted deployments to confirm it remains at the default secured value.
- Alert on creation of new Owner or Administrator accounts and on changes to webhook or integration configurations.
How to Mitigate CVE-2026-105643
Immediate Actions Required
- Upgrade all Ghost instances to version 6.67.0 or later without delay.
- Review staff accounts and revoke access for any Contributor or Author accounts that are not actively required.
- Audit recent posts and drafts for embed cards containing suspicious content, and rotate admin credentials and API keys if compromise is suspected.
Patch Information
Ghost version 6.67.0 fixes the stored XSS condition in embed card rendering. Self-hosted operators must also leave the newly introduced security.embedPreviewUrl configuration option at its default value to retain the mitigation. See the Ghost security advisory GHSA-69qc-f5m6-889c for complete remediation guidance.
Workarounds
- If immediate upgrade is not feasible, restrict post-authoring privileges to a minimum set of trusted staff accounts.
- Instruct administrators to avoid opening drafts authored by lower-privileged staff until the patched version is deployed.
- On self-hosted instances, confirm that no custom configuration overrides the default value of security.embedPreviewUrl.
# Upgrade a self-hosted Ghost instance to the patched release
ghost update --version 6.67.0
# Verify the running version after upgrade
ghost version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.