CVE-2026-70588: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in TryGhost Ghost
CVE-2026-70588 is a medium severity cross-site scripting (XSS) vulnerability in the Ghost content management system. The issue affects versions from 5.26.0 up to but not including 6.54.1. It arises from improper sanitization of imported content via the Universal Import feature in Ghost Admin, allowing malicious scripts to be injected into post content. The vulnerability is fixed in version 6.54.1.
AI Analysis
Technical Summary
Ghost, a Node.js CMS, contains a cross-site scripting vulnerability (CWE-79) in its Universal Import feature within Ghost Admin. Versions starting from 5.26.0 through 6.54.0 fail to properly neutralize input during web page generation, specifically when importing content. This allows an attacker with high privileges and no user interaction to inject malicious scripts into post content. The vulnerability is addressed in version 6.54.1.
Potential Impact
The vulnerability allows an attacker with high privileges to inject malicious scripts into post content, potentially impacting the integrity of the content and user experience. There is no confidentiality or availability impact indicated. Exploitation requires high privileges and no user interaction is needed. No known exploits are reported in the wild.
Mitigation Recommendations
Upgrade Ghost to version 6.54.1 or later, where the vulnerability has been fixed. Since no official remediation level or patch link is provided, users should verify the upgrade from the vendor's official release notes or advisory. No additional mitigation steps are specified.
CVE-2026-70588: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in TryGhost Ghost
Description
CVE-2026-70588 is a medium severity cross-site scripting (XSS) vulnerability in the Ghost content management system. The issue affects versions from 5.26.0 up to but not including 6.54.1. It arises from improper sanitization of imported content via the Universal Import feature in Ghost Admin, allowing malicious scripts to be injected into post content. The vulnerability is fixed in version 6.54.1.
CVSS v3.1
Score 5.0medium
Affected software
TryGhost
Ghost
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Ghost, a Node.js CMS, contains a cross-site scripting vulnerability (CWE-79) in its Universal Import feature within Ghost Admin. Versions starting from 5.26.0 through 6.54.0 fail to properly neutralize input during web page generation, specifically when importing content. This allows an attacker with high privileges and no user interaction to inject malicious scripts into post content. The vulnerability is addressed in version 6.54.1.
Potential Impact
The vulnerability allows an attacker with high privileges to inject malicious scripts into post content, potentially impacting the integrity of the content and user experience. There is no confidentiality or availability impact indicated. Exploitation requires high privileges and no user interaction is needed. No known exploits are reported in the wild.
Mitigation Recommendations
Upgrade Ghost to version 6.54.1 or later, where the vulnerability has been fixed. Since no official remediation level or patch link is provided, users should verify the upgrade from the vendor's official release notes or advisory. No additional mitigation steps are specified.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-04T19:50:27.327Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a72559fbf8831d53976f81a
Added to database: 08/04/2026, 21:11:59 UTC
Last enriched: 08/12/2026, 15:14:32 UTC
Last updated: 09/17/2026, 22:01:37 UTC
Views: 63
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.