{"id":"GHSA-8575-cr6v-7jh4","summary":"Ghost: Stored XSS via SVG Uploads Bypassing Sanitization","details":"### Impact\n\nSVG media thumbnails, and SVG images uploaded with a non-SVG file extension, were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions.\n\n### Vulnerable versions\n\nThis vulnerability is present in Ghost from v4.22.0 up to v6.64.0.\n\n### Patches\n\nv6.65.0 contains a fix for this issue.\n\n### How to update\n\nFor self-hosters using Docker, find [Docker's official Ghost image here](https://hub.docker.com/_/ghost). Updating a Docker-based Ghost instance [is documented here](https://docs.ghost.org/install/docker#updating-ghost). \n\nIf your Ghost is a Ghost-CLI install see our documentation on [updating it to the latest version here](https://docs.ghost.org/update). \n\n### References\n\nGhost thanks [Ibrahim AlJaafreh](https://cystack.ps) of Cystack Red Team, [Anand Prajapati](https://www.linkedin.com/in/anand-prajapati-7a265a369/), [白墨](https://github.com/5255fgh), and [Nhat Anh Vu](https://github.com/nhattanhh) for disclosing this vulnerability responsibly.\n\n### For more information\n\nIf you have any questions or comments about this advisory, email us at [security@ghost.org](mailto:security@ghost.org).","aliases":["CVE-2026-105649"],"modified":"2026-10-07T20:45:05.340601920Z","published":"2026-10-07T20:35:22Z","database_specific":{"github_reviewed_at":"2026-10-07T20:35:22Z","nvd_published_at":"2026-10-05T20:17:13Z","cwe_ids":["CWE-434","CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-8575-cr6v-7jh4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105649"},{"type":"WEB","url":"https://github.com/TryGhost/Ghost/issues/30919"},{"type":"WEB","url":"https://github.com/TryGhost/Ghost/commit/80686226d23df56749f6b7ebb484850a8eba8072"},{"type":"PACKAGE","url":"https://github.com/TryGhost/Ghost"},{"type":"WEB","url":"https://github.com/TryGhost/Ghost/releases/tag/v6.65.0"}],"affected":[{"package":{"name":"ghost","ecosystem":"npm","purl":"pkg:npm/ghost"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.22.0"},{"fixed":"6.65.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-8575-cr6v-7jh4/GHSA-8575-cr6v-7jh4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"}]}