CVE WATCH / VULNERABILITY DETAIL
CVE-2026-103277
HIGHCVSS 8.1NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in the context of a staff user's admin session, potentially compr
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog