PatchSiren cyber security CVE debrief
CVE-2026-105643 TryGhost CVE debrief
CVE-2026-105643 debrief: Ghost Stored XSS via Embed Card Previews. A stored XSS vulnerability in Ghost allows staff users to store scripts in post content that can run when another staff user opens the post in the editor, potentially resulting in compromise of that user's admin session. This issue affects Ghost from v6.34.0 up to v6.65.0 and is fixed in v6.67.0. Self-hosted sites should leave the new `security.embedPreviewUrl` config option at its default. Defenders responsible for Ghost installations, particularly those with staff users who can create or edit post content, should assess exposure and prioritize updates to version 6.67.0 or later.
- Vendor
- TryGhost
- Product
- ghost
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Ghost installations, particularly those with staff users who can create or edit post content, should assess exposure and prioritize updates to version 6.67.0 or later.
Why it matters
Defenders should prioritize updating Ghost installations to version 6.67.0 or later, review staff user roles and access controls, and configure the new `security.embedPreviewUrl` config option to its default value for self-hosted sites, as a stored XSS vulnerability allows staff users to store scripts in post content that can run when another staff user opens the post in the editor.
- Possible compromise of admin sessions for staff users who open posts with malicious content
- Elevation of privileges for attackers who can create or edit post content
- Potential for lateral movement within Ghost installations
- Need for verification of current Ghost version and exposure to vulnerable versions
Technical summary
The CVE record and source item describe a stored XSS vulnerability in Ghost, allowing staff users to store scripts in post content that can run when another staff user opens the post in the editor, potentially resulting in compromise of that user's admin session. This issue affects Ghost from v6.34.0 up to v6.65.0 and is fixed in v6.67.0. The vulnerability can be mitigated by updating Ghost installations to version 6.67.0 or later, reviewing staff user roles and access controls, and configuring the new `security.embedPreviewUrl` config option to its default value for self-hosted sites.
Defensive priority
Defenders should prioritize updating Ghost installations to version 6.67.0 or later, and review staff user roles and access controls.
Recommended defensive actions
- Update Ghost installations to version 6.67.0 or later
- Review staff user roles and access controls
- Configure the new `security.embedPreviewUrl` config option to its default value for self-hosted sites
- Confirm whether affected Ghost deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed Ghost systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed Ghost assets that need extra review
- Track exceptions, retest remediated Ghost assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on a stored XSS vulnerability in Ghost, allowing staff users to store scripts in post content that can run when another staff user opens the post in the editor.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105643 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105643
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105643 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105643
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Ghost: Stored XSS via Embed Card Previews
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-69qc-f5m6-889c.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/security/advisories/GHSA-69qc-f5m6-889c
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/penpot/penpot/security/advisories/GHSA-qvq5-c536-pmx8
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.