High severity8.1NVD Advisory· Published Oct 1, 2026
CVE-2026-103277
CVE-2026-103277
Description
Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in the context of a staff user's admin session, potentially compromising administrative access.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.