PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105643 TryGhost CVE debrief

CVE-2026-105643 debrief: Ghost Stored XSS via Embed Card Previews. A stored XSS vulnerability in Ghost allows staff users to store scripts in post content that can run when another staff user opens the post in the editor, potentially resulting in compromise of that user's admin session. This issue affects Ghost from v6.34.0 up to v6.65.0 and is fixed in v6.67.0. Self-hosted sites should leave the new `security.embedPreviewUrl` config option at its default. Defenders responsible for Ghost installations, particularly those with staff users who can create or edit post content, should assess exposure and prioritize updates to version 6.67.0 or later.

Vendor
TryGhost
Product
ghost
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Ghost installations, particularly those with staff users who can create or edit post content, should assess exposure and prioritize updates to version 6.67.0 or later.

Why it matters

Defenders should prioritize updating Ghost installations to version 6.67.0 or later, review staff user roles and access controls, and configure the new `security.embedPreviewUrl` config option to its default value for self-hosted sites, as a stored XSS vulnerability allows staff users to store scripts in post content that can run when another staff user opens the post in the editor.

  • Possible compromise of admin sessions for staff users who open posts with malicious content
  • Elevation of privileges for attackers who can create or edit post content
  • Potential for lateral movement within Ghost installations
  • Need for verification of current Ghost version and exposure to vulnerable versions

Technical summary

The CVE record and source item describe a stored XSS vulnerability in Ghost, allowing staff users to store scripts in post content that can run when another staff user opens the post in the editor, potentially resulting in compromise of that user's admin session. This issue affects Ghost from v6.34.0 up to v6.65.0 and is fixed in v6.67.0. The vulnerability can be mitigated by updating Ghost installations to version 6.67.0 or later, reviewing staff user roles and access controls, and configuring the new `security.embedPreviewUrl` config option to its default value for self-hosted sites.

Defensive priority

Defenders should prioritize updating Ghost installations to version 6.67.0 or later, and review staff user roles and access controls.

Recommended defensive actions

  • Update Ghost installations to version 6.67.0 or later
  • Review staff user roles and access controls
  • Configure the new `security.embedPreviewUrl` config option to its default value for self-hosted sites
  • Confirm whether affected Ghost deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed Ghost systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed Ghost assets that need extra review
  • Track exceptions, retest remediated Ghost assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on a stored XSS vulnerability in Ghost, allowing staff users to store scripts in post content that can run when another staff user opens the post in the editor.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105643 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105643

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105643 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105643

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Ghost: Stored XSS via Embed Card Previews

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-69qc-f5m6-889c.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost/security/advisories/GHSA-69qc-f5m6-889c

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/penpot/penpot/security/advisories/GHSA-qvq5-c536-pmx8

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.