Junglewise Threat Intelligence

CVE-2026-70596: Ghost stored XSS in feature image captions

CVE-2026-70596 · Severity: medium · CVSS 4.3 · Published 2026-08-05

Executive brief

Ghost is a popular open-source content management system used for professional publishing. A security flaw in how the platform handles image captions allows a staff member to inject malicious code into a post. If another administrator views this content, the attacker could hijack their session and gain full control over the website.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Ghost due to improper input validation in feature image captions. An attacker with staff-level privileges can create a post containing a malicious payload that executes in the context of other users' browsers. If a user with higher privileges (such as an Administrator) views the affected post in the Ghost Admin interface, the attacker can hijack their session, leading to full privilege escalation. The vulnerability is present in versions 4.9.0 through 6.54.0 and is fixed in version 6.54.1.

Affected products

  • Ghost Foundation Ghost >= 4.9.0, < 6.54.1

Timeline

  • 2026-07-30: disclosed
  • 2026-08-05: advisory
  • 2026-08-05: patched: Version 6.54.1 released

References

Related threats