Ghost CMS: Four Vulnerabilities Including SVG Exploits Disclosed Together
Four vulnerabilities impacting Ghost CMS were disclosed on October 5th, 2026, including high-severity flaws related to SVG handling and script injection.

Key findings
- Four vulnerabilities in Ghost CMS disclosed on October 5th, 2026, with three rated High severity.
- High severity flaws include SVG handling issues leading to script injection and arbitrary command execution.
- CVE-2026-105645 (Medium) allows denial-of-service via crafted requests to the media inliner.
- Vulnerabilities affect various versions, with patches available in newer releases like 6.67.0.
On October 5th, 2026, a batch of four vulnerabilities was disclosed for Ghost, a Node.js content management system. These vulnerabilities, disclosed within a one-hour window, range in severity from Medium to High, with three rated as High. The disclosures highlight potential risks including stored cross-site scripting (XSS), arbitrary command execution, and denial-of-service conditions, impacting various versions of the Ghost platform.
Two of the high-severity vulnerabilities, CVE-2026-105649 and CVE-2026-105643, relate to improper handling of SVG files and embed cards, respectively. CVE-2026-105649, affecting versions from 4.22.0 to 6.65.0, allowed for the storage of unsanitized SVG media thumbnails and images with non-SVG extensions. This could enable staff users, including Contributors, to host malicious scripts on the site's domain, potentially leading to the compromise of other staff accounts. Similarly, CVE-2026-105643, impacting versions 6.34.0 to 6.67.0, involved embed cards in the Ghost editor bypassing XSS protections. This allowed any staff user to store scripts in post content, which would execute when another staff user edited the post.
Another high-severity vulnerability, CVE-2026-105642 (CVSSv3 8.8), present in versions 6.56.0 to 6.67.0, stemmed from a vulnerability in an image processing library's SVG handling. This flaw could allow any staff user to create a bookmark card pointing to an attacker-controlled website, leading to the execution of arbitrary commands on the server.
The remaining vulnerability, CVE-2026-105645, is a Medium severity issue affecting versions 5.37.0 to 6.67.0. A crafted request to the external media inliner could trigger excessive CPU usage, rendering the Ghost server unresponsive. Exploiting this particular vulnerability requires Administrator access.
The vulnerabilities were patched in various versions. Specifically, CVE-2026-105645 was fixed in version 6.67.0. While specific patch versions for the other CVEs are not detailed in the provided information, the range of affected versions suggests that users should update to the latest available Ghost release to ensure they are protected against these issues. The clustered disclosure of these vulnerabilities underscores the importance of timely patching for Ghost CMS users to mitigate risks associated with script injection, command execution, and denial-of-service attacks.