CVE-2026-105642

Source
https://cve.org/CVERecord?id=CVE-2026-105642
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105642.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105642
Aliases
  • GHSA-788w-68h3-cvxp
Published
2026-10-05T18:31:05Z
Modified
2026-10-07T02:31:11Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Ghost: Remote Code Execution via Bookmark Card Images
Details

Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attacker-controlled website, resulting in arbitrary commands being run on the Ghost server. This issue is fixed in version 6.67.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-1395",
        "CWE-94"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105642.json"
}
References

Affected packages

Git / github.com/tryghost/ghost

Affected ranges

Type
GIT
Repo
https://github.com/tryghost/ghost
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "6.56.0"
        },
        {
            "fixed": "6.67.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v6.*
v6.56.0
v6.57.0
v6.57.1
v6.58.0
v6.59.0
v6.60.0
v6.61.0
v6.62.0
v6.63.0
v6.64.0
v6.65.0
v6.66.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105642.json"