Ghost Vulnerability CVE-2026-105642 Enables Remote Code Execution
Article Content
- •CVE-2026-105642 allows remote code execution via SVG handling in Ghost.
- •Affected versions range from v6.56.0 to v6.65.0, with a fix in v6.67.0.
- •Users are advised to update their Ghost installations immediately.
A vulnerability identified as CVE-2026-105642 affects the Ghost image processing library, specifically its handling of SVG files. This flaw allows any staff user, including Contributors, to create a bookmark card linked to an attacker-controlled website, which can execute arbitrary commands on the Ghost server. The vulnerability impacts Ghost versions from v6.56.0 to v6.65.0, with a fix included in v6.67.0 released on October 5, 2026. Users are urged to update their installations to mitigate this risk. The vulnerability was disclosed responsibly by researcher Rafael B. The CVSS score for this vulnerability is 8.8, categorizing it as high severity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Ghost and CVE-2026-105642 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of Ghost are affected?
What should I do to protect my Ghost installation?
Who disclosed this vulnerability?
Continue Reading
Ghost CMS Vulnerabilities: Authentication Bypass and Account Modification Risks Two vulnerabilities have been identified in the Ghost CMS platform affecting versions 5.2.0 to 6.62.0 and 6.20.0 to 6.57.1. The first vulnerability allows unauthenticated account modification during Stripe checkout, while the second enables authentication bypass via session handling. These flaws could potentially…