CVE-2026-70596 Details
Description
Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin session, resulting in privilege escalation. This issue is fixed in 6.54.1.
A cross-site scripting vulnerability has been identified in Ghost, a Node.js content management system, affecting versions 4.9.0 prior to 6.54.1. The issue arises from improper input validation, which allowed staff users to embed malicious content in the feature image caption of posts. This embedded content could hijack another staff user's Ghost Admin session, leading to unauthorized privilege escalation.
Users can update to Ghost version 6.54.1, which includes a fix for this vulnerability. Self-hosted users can find the official Ghost Docker image on Docker Hub and follow the documentation for updating a Docker-based Ghost instance. For those using Ghost-CLI, instructions for updating to the latest version are available in the Ghost documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 5, 2026CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/TryGhost/Ghost/commit/a8bea3a4ceec4c852b880f4885119453c3d8588e | [email protected] | Source CodeVendor |
| https://github.com/TryGhost/Ghost/pull/29635 | [email protected] | Issue TrackingVendor |
| https://github.com/TryGhost/Ghost/releases/tag/v6.54.1 | [email protected] | Release NotesVendor |
| https://github.com/TryGhost/Ghost/security/advisories/GHSA-pr22-p9rp-2cqv | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ghost | >= 4.9.0, < 6.54.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |
Volerion