{"id":"GHSA-gv6q-2m97-882h","summary":"Ghost vulnerable to XSS via malicious Portal preview links","details":"### Impact\nAn attacker was able to craft a malicious link that, when accessed by an authenticated staff user or member, would execute JavaScript with the victim's permissions, potentially leading to account takeover. \n\n### Vulnerable versions\nThis vulnerability is present in Ghost versions:\n- v5.43.0 to v5.120.4\n- v6.0.0 to v6.14.0\n\nAs well as in Portal versions:\n- v2.29.1 to v2.51.4\n- v2.52.0 to v2.57.0\n\n### Patches\nGhost automatically loads the latest patch of the members Portal component via CDN. Therefore:\n- For Ghost 5.x users, upgrading to v5.121.0 or later fixes the vulnerability (loads Portal v2.51.5, which contains the patch)\n- For Ghost 6.x users, upgrading to v6.15.0 or later fixes the vulnerability (loads Portal v2.57.1, which contains the patch)\n\nFor Ghost installations using a customised or self-hosted version of Portal, it will be necessary to manually rebuild from or update to the latest patch version.\n\n### References\nGhost thanks Younes Belalia for discovering and disclosing this vulnerability responsibly.\n\n### For more information\nIf users have any questions or comments about this advisory, email Ghost at [security@ghost.org](mailto:security@ghost.org).","aliases":["BIT-ghost-2026-24778","CVE-2026-24778"],"modified":"2026-02-03T09:26:16.637328Z","published":"2026-01-28T16:11:59Z","database_specific":{"github_reviewed_at":"2026-01-28T16:11:59Z","nvd_published_at":"2026-01-27T22:15:57Z","cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-gv6q-2m97-882h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24778"},{"type":"WEB","url":"https://github.com/TryGhost/Ghost/commit/da858e640e88e69c1773a7b7ecdc2008fa143849"},{"type":"PACKAGE","url":"https://github.com/TryGhost/Ghost"}],"affected":[{"package":{"name":"ghost","ecosystem":"npm","purl":"pkg:npm/ghost"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.43.0"},{"fixed":"5.121.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-gv6q-2m97-882h/GHSA-gv6q-2m97-882h.json"}},{"package":{"name":"@tryghost/portal","ecosystem":"npm","purl":"pkg:npm/%40tryghost/portal"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.29.1"},{"fixed":"2.51.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-gv6q-2m97-882h/GHSA-gv6q-2m97-882h.json"}},{"package":{"name":"@tryghost/portal","ecosystem":"npm","purl":"pkg:npm/%40tryghost/portal"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.52.0"},{"fixed":"2.57.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-gv6q-2m97-882h/GHSA-gv6q-2m97-882h.json"}},{"package":{"name":"ghost","ecosystem":"npm","purl":"pkg:npm/ghost"},"ranges":[{"type":"SEMVER","events":[{"introduced":"6.0.0"},{"fixed":"6.15.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-gv6q-2m97-882h/GHSA-gv6q-2m97-882h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}