CVE-2026-105651 Overview
Ghost, a Node.js content management system, contains a stored cross-site scripting (XSS) vulnerability in its bookmark card feature. From version 5.94.0 until 6.64.0, Ghost fetched external resources for bookmark icons and thumbnails without validating file types. This allowed non-image files, including HTML documents, to be stored and served from the site's own domain. Any staff user, including low-privileged Contributors, could exploit this flaw to host arbitrary HTML on the Ghost instance. The hosted content executes in the context of the site's origin, enabling theft of other staff users' admin sessions. The issue is tracked as [CWE-79] and fixed in version 6.64.0.
Critical Impact
Any authenticated Contributor can host arbitrary HTML on the Ghost domain and hijack administrator sessions through same-origin script execution.
Affected Products
- Ghost (Node.js CMS) versions 5.94.0 through 6.63.x
- Ghost self-hosted deployments using bookmark cards
- Ghost staff user accounts with Contributor privileges or higher
Discovery Timeline
- 2026-10-05 - CVE-2026-105651 published to NVD
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-105651
Vulnerability Analysis
The vulnerability resides in Ghost's oEmbed service, specifically in the bookmark card creation workflow. When a staff user creates a bookmark card pointing to an external URL, Ghost fetches the referenced page's icon and thumbnail. The service then stores these fetched resources on the Ghost server and serves them from the site's domain.
Ghost did not verify that the fetched content was actually an image file. An attacker-controlled server could return an HTML document with an image/* content type or an image-like URL path. Ghost would store the HTML document and later serve it from a path on the Ghost domain. Browsers rendering that URL execute embedded JavaScript in the Ghost origin.
Because administrator sessions share the same origin, scripts hosted this way can read session cookies, call privileged admin API endpoints, and persist malicious changes to the site.
Root Cause
The root cause is missing input validation on fetched remote content [CWE-79]. The oEmbed service in ghost/core/core/server/services/oembed/oembed-service.js lacked a file-type check before storing bookmark icons and thumbnails. The patch introduces an unsupportedImage error path that rejects content which is not a valid supported image format.
Attack Vector
Exploitation requires an authenticated staff user and user interaction from a victim who views the attacker-hosted asset. The attacker hosts an HTML payload at a URL that Ghost treats as a bookmark image source. They then create a bookmark card targeting that URL, causing Ghost to fetch and store the payload. Sharing the resulting hosted URL to an administrator triggers script execution in the Ghost origin.
// Patch excerpt - ghost/core/core/server/services/oembed/oembed-service.js
unableToFetchOembed: 'Unable to fetch requested embed.',
unauthorized: 'URL contains a private resource.',
unconvertibleSvg: 'SVG image is too large or compressed to convert.',
+ unsupportedImage: 'Image is not a supported file type.',
};
const SVG_RASTER_SIZE = 256;
Source: GitHub Commit b41fe3f
Detection Methods for CVE-2026-105651
Indicators of Compromise
- Bookmark card entries referencing external image URLs that return non-image MIME types in server logs.
- Files stored under Ghost's content image directory with .html, .svg, or ambiguous extensions containing <script> tags.
- Unexpected admin API calls originating from browser sessions shortly after a staff user views a bookmark card.
- Newly created or modified staff accounts without a corresponding admin action trail.
Detection Strategies
- Scan Ghost's content storage directory for files with image extensions whose magic bytes do not match a valid image format.
- Review audit logs for bookmark card creation events by Contributor-tier accounts, correlated with outbound HTTP fetches to attacker-controlled hosts.
- Monitor web server logs for responses serving text/html from image asset paths.
Monitoring Recommendations
- Alert on any staff user privilege change or new Owner/Administrator session originating from an unusual IP or user agent.
- Track outbound HTTP requests from the Ghost oEmbed service to unknown or recently registered domains.
- Enable centralized logging for the Ghost admin API and review session cookie usage anomalies.
How to Mitigate CVE-2026-105651
Immediate Actions Required
- Upgrade Ghost to version 6.64.0 or later without delay.
- Invalidate all active admin sessions and force password resets for Owner, Administrator, and Editor accounts.
- Audit existing bookmark cards and remove any that reference suspicious external hosts.
- Review the Ghost content images directory for stored files that are not valid images and remove them.
Patch Information
The fix is included in Ghost 6.64.0. The patch adds an unsupportedImage validation path in the oEmbed service, rejecting fetched content that is not a supported image file type. See the GitHub Security Advisory GHSA-347q-26qq-h2p6 and the Ghost v6.64.0 Release Notes for full remediation details. Related discussion is tracked in Ghost Issue #30761.
Workarounds
- Restrict the Contributor and higher roles to trusted personnel until the upgrade is applied.
- Deploy a web application firewall rule to block responses with text/html content types served from Ghost content image paths.
- Serve Ghost content assets from a separate cookieless domain to prevent same-origin session theft from stored HTML files.
# Upgrade Ghost via the ghost-cli to the patched release
ghost update 6.64.0
# Verify the installed version matches the patched release
ghost version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.