CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105651

HIGHCVSS 7.3NVD feed

Published 5 October 2026 · tracked since 6 October 2026

Description

Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from an external website as bookmark icons or thumbnails. This allowed any staff user, including Contributors, to host arbitrary HTML on the site's domain,

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-105651 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105651

HIGHCVSS 7.3NVD feed

Published 5 October 2026 · tracked since 6 October 2026

Description

Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from an external website as bookmark icons or thumbnails. This allowed any staff user, including Contributors, to host arbitrary HTML on the site's domain,

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]