Skip to content
Ghost Vulnerability CVE-2026-105642 Enables Remote Code Execution

Ghost Vulnerability CVE-2026-105642 Enables Remote Code Execution

First seen 8 Oct 2026, 06:31 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 07:31 UTC
  • •CVE-2026-105642 allows remote code execution via SVG handling in Ghost.
  • •Affected versions range from v6.56.0 to v6.65.0, with a fix in v6.67.0.
  • •Users are advised to update their Ghost installations immediately.

A vulnerability identified as CVE-2026-105642 affects the Ghost image processing library, specifically its handling of SVG files. This flaw allows any staff user, including Contributors, to create a bookmark card linked to an attacker-controlled website, which can execute arbitrary commands on the Ghost server. The vulnerability impacts Ghost versions from v6.56.0 to v6.65.0, with a fix included in v6.67.0 released on October 5, 2026. Users are urged to update their installations to mitigate this risk. The vulnerability was disclosed responsibly by researcher Rafael B. The CVSS score for this vulnerability is 8.8, categorizing it as high severity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-05
CVE-2026-105642 published
Ghost disclosed a vulnerability allowing remote code execution via SVG handling, affecting versions 6.56.0 to 6.65.0.
Article 1
2026-10-08
Advisories published
GitHub published advisories detailing the vulnerability and urging users to update to version 6.67.0.
Article 2

More articles in this cluster (4)

Following this threat?

Track Ghost and CVE-2026-105642 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Ghost are affected?
Ghost versions from 6.56.0 to 6.65.0 are affected by CVE-2026-105642.
What should I do to protect my Ghost installation?
Update your Ghost installation to version 6.67.0 or later to mitigate the vulnerability.
Who disclosed this vulnerability?
The vulnerability was disclosed responsibly by researcher Rafael B.