OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105642

HIGH · CVSS 8.8 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A vulnerability in the image processing library of the Ghost Node.js content management system allows any staff user, including Contributors, to create a bookmark card for an attacker-controlled website, potentially executing arbitrary commands on the server. This high-severity issue affects versions 6.56.0 to 6.67.0 and should be prioritized by organizations using these versions to mitigate the risk of server compromise. Users are urged to upgrade to version 6.67.0 or later to address this security flaw.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105642
Severity
HIGH
CVSS
8.8
EPSS
0.25%

Original NVD Description

Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attacker-controlled website, resulting in arbitrary commands being run on the Ghost server. This issue is fixed in version 6.67.0.