CVE-2026-24778

Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0.0 through 6.14.0, an attacker was able to craft a malicious link that, when accessed by an authenticated staff user or member, would execute JavaScript with the victim's permissions, potentially leading to account takeover. Ghost Portal versions 2.29.1 through 2.51.4 and 2.52.0 through 2.57.0 were vulnerable to this issue. Ghost automatically loads the latest patch of the members Portal component via CDN. For Ghost 5.x users, upgrading to v5.121.0 or later fixes the vulnerability. v5.121.0 loads Portal v2.51.5, which contains the patch. For Ghost 6.x users, upgrading to v6.15.0 or later fixes the vulnerability. v6.15.0 loads Portal v2.57.1, which contains the patch. For Ghost installations using a customized or self-hosted version of Portal, it will be necessary to manually rebuild from or update to the latest patch version.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*
cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*
cpe:2.3:a:ghost:portal:*:*:*:*:*:node.js:*:*
cpe:2.3:a:ghost:portal:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 10:23

Type Values Removed Values Added
Summary
  • (es) Ghost es un sistema de gestión de contenido de código abierto. En las versiones de Ghost 5.43.0 a 5.12.04 y 6.0.0 a 6.14.0, un atacante pudo crear un enlace malicioso que, cuando era accedido por un usuario de personal o miembro autenticado, ejecutaría JavaScript con los permisos de la víctima, lo que podría llevar a la toma de control de la cuenta. Las versiones de Ghost Portal 2.29.1 a 2.51.4 y 2.52.0 a 2.57.0 eran vulnerables a este problema. Ghost carga automáticamente el último parche del componente Portal de miembros a través de CDN. Para los usuarios de Ghost 5.x, actualizar a la v5.121.0 o posterior corrige la vulnerabilidad. La v5.121.0 carga Portal v2.51.5, que contiene el parche. Para los usuarios de Ghost 6.x, actualizar a la v6.15.0 o posterior corrige la vulnerabilidad. La v6.15.0 carga Portal v2.57.1, que contiene el parche. Para las instalaciones de Ghost que utilizan una versión personalizada o autoalojada de Portal, será necesario reconstruir manualmente desde o actualizar a la última versión del parche.

02 Feb 2026, 15:21

Type Values Removed Values Added
First Time Ghost portal
Ghost
Ghost ghost
References () https://github.com/TryGhost/Ghost/commit/da858e640e88e69c1773a7b7ecdc2008fa143849 - () https://github.com/TryGhost/Ghost/commit/da858e640e88e69c1773a7b7ecdc2008fa143849 - Patch
References () https://github.com/TryGhost/Ghost/security/advisories/GHSA-gv6q-2m97-882h - () https://github.com/TryGhost/Ghost/security/advisories/GHSA-gv6q-2m97-882h - Vendor Advisory
CPE cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*
cpe:2.3:a:ghost:portal:*:*:*:*:*:node.js:*:*

27 Jan 2026, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 22:15

Updated : 2026-06-17 10:23


NVD link : CVE-2026-24778

Mitre link : CVE-2026-24778

CVE.ORG link : CVE-2026-24778


JSON object : View

Products Affected

ghost

  • ghost
  • portal
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')