CVE-2026-70596

MEDIUM

Ghost: Cross-Site Scripting in Feature Image Captions

Title source: cna
STIX 2.1

Description

Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin session, resulting in privilege escalation. This issue is fixed in 6.54.1.

Scores

CVSS v3 4.3
EPSS 0.0018
EPSS Percentile 7.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
npm/ghost 4.9.0 - 6.54.1npm
TryGhost/Ghost >= 4.9.0, < 6.54.1
Published Aug 05, 2026
Tracked Since Aug 05, 2026