Threat Advisory

Ghost Flaw Lets Attackers Run Arbitrary Commands via Bookmark Card Images

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability affecting ghost versions >= 6.56.0, < 6.67.0 affecting ghost versions This vulnerability is present in Ghost from v6 (CVE-2026-105642, CVSS score of 8.8) exists in Ghost's image processing library, allowing remote code execution via bookmark card images created by staff users for attacker-controlled websites. This flaw is present in versions from v6.56.0 up to v6.65.0 and exposes the system to potential attacks, potentially leading to unauthorized access, data tampering, or complete system compromise. The vulnerability can be exploited through a remote attack vector with low complexity, requiring no privileges and user interaction for successful exploitation.

RECOMMENDATION:

We recommend you to update Ghost to version 6.67.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability affecting ghost versions >= 6.56.0, < 6.67.0 affecting ghost versions This vulnerability is present in Ghost from v6 (CVE-2026-105642, CVSS score of 8.8) exists in Ghost's image processing library, allowing remote code execution via bookmark card images created by staff users for attacker-controlled websites. This flaw is present in versions from v6.56.0 up to v6.65.0 and exposes the system to potential attacks, potentially leading to unauthorized access, data tampering, or complete system compromise. The vulnerability can be exploited through a remote attack vector with low complexity, requiring no privileges and user interaction for successful exploitation.

RECOMMENDATION:

We recommend you to update Ghost to version 6.67.0.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu