CVE-2026-103277

Source
https://cve.org/CVERecord?id=CVE-2026-103277
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103277.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-103277
Aliases
  • GHSA-8vhf-xxpj-4qrg
Published
2026-10-01T10:42:14Z
Modified
2026-10-03T03:46:33Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Ghost 2.5.0 before 6.34.0 Untrusted Script Execution via oEmbed
Details

Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in the context of a staff user's admin session, potentially compromising administrative access.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-79"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103277.json"
}
References

Affected packages

Git / github.com/tryghost/ghost

Affected ranges

Type
GIT
Repo
https://github.com/tryghost/ghost
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.5.0"
        },
        {
            "fixed":  "6.34.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103277.json"