HIGH 8.6 NVD
CVE-2026-103277
Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hoste
Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in the context of a staff user's admin session, potentially compromising administrative access.
References
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-8vhf-xxpj-4qrg
- https://www.vulncheck.com/advisories/ghost-2.5.0-before-6.34.0-untrusted-script-execution-
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.