Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

CVE-2026-105644: CVE-2026-105644: Stored Cross-Site Scripting via Malicious SVG Content Import in Ghost CMS

CVE-2026-105644: Stored Cross-Site Scripting via Malicious SVG Content Import in Ghost CMS Vulnerability ID: CVE-2026-105644 CVSS Score: 6.8 Published: 2026-10-07 A Stored Cross-Site Scripting (XSS) and Unrestricted

CVE-2026-105644: Stored Cross-Site Scripting via Malicious SVG Content Import in Ghost CMS

Vulnerability ID: CVE-2026-105644
CVSS Score: 6.8
Published: 2026-10-07

A Stored Cross-Site Scripting (XSS) and Unrestricted Upload of File with Dangerous Type vulnerability in Ghost CMS (versions 4.0.0 to 6.66.x) allows remote attackers to execute arbitrary JavaScript in the context of an administrator's session. The flaw lies in the content import subsystem, which extracted and stored SVG files without sanitization or binary verification.

TL;DR

Ghost CMS failed to sanitize SVG files included inside bulk content imports (ZIP files). Attackers can trick administrators into importing a malicious ZIP containing crafted SVGs with embedded JavaScript, leading to stored XSS and complete CMS takeover.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-79, CWE-434
  • Attack Vector: Network
  • CVSS Score: 6.8 (Medium)
  • EPSS Score: 0.0032 (0.32%)
  • Impact: Stored XSS / Session Hijacking
  • Exploit Status: Proof of Concept (PoC)
  • KEV Status: Not Listed

Affected Systems

  • Ghost Content Management System (CMS)
  • Ghost: >= 4.0.0, < 6.67.0 (Fixed in: 6.67.0)

Code Analysis

Commit: 1be06f4

Add strict SVG validation, sanitizer workflows, magic-byte checking and decoder restrictions inside the image importer handler.

Mitigation Strategies

  • Upgrade Ghost CMS platform core to version 6.67.0 or above
  • Enforce explicit Content Security Policy (CSP) headers over uploaded resources
  • Implement domain-level sandboxing for user-supplied uploaded files

Remediation Steps:

  1. Navigate to the host system shell hosting Ghost
  2. Execute command 'ghost update' to pull and install the latest secure package
  3. Add a strict 'Content-Security-Policy' header rule inside reverse proxy configurations for target image directory endpoints

References

Read the full report for CVE-2026-105644 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.