BIT-ghost-2026-103277

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/ghost/BIT-ghost-2026-103277.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-ghost-2026-103277
Aliases
Published
2026-10-09T10:44:55Z
Modified
2026-10-09T12:10:49Z
Summary
Ghost 2.5.0 before 6.34.0 Untrusted Script Execution via oEmbed
Details

Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in the context of a staff user's admin session, potentially compromising administrative access.

Database specific
{
    "cpes": [
        "cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / ghost

Package

Name
ghost
Purl
pkg:bitnami/ghost

Severity

  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
2.5.0
Fixed
6.34.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/ghost/BIT-ghost-2026-103277.json"