SVG media thumbnails, and SVG images uploaded with a non-SVG file extension, were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions.
This vulnerability is present in Ghost from v4.22.0 up to v6.64.0.
v6.65.0 contains a fix for this issue.
For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.
If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.
Ghost thanks Ibrahim AlJaafreh of Cystack Red Team, Anand Prajapati, 白墨, and Nhat Anh Vu for disclosing this vulnerability responsibly.
If you have any questions or comments about this advisory, email us at security@ghost.org.
{
"cwe_ids": [
"CWE-434",
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T20:35:22Z",
"nvd_published_at": "2026-10-05T20:17:13Z",
"severity": "HIGH"
}