CyberRota Analysis
AI-GeneratedA vulnerability in the image processing library of the Ghost Node.js content management system allows any staff user, including Contributors, to create a bookmark card for an attacker-controlled website, potentially executing arbitrary commands on the server. This high-severity issue affects versions 6.56.0 to 6.67.0 and should be prioritized by organizations using these versions to mitigate the risk of server compromise. Users are urged to upgrade to version 6.67.0 or later to address this security flaw.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attacker-controlled website, resulting in arbitrary commands being run on the Ghost server. This issue is fixed in version 6.67.0.