CVE-2026-70588

medium

Description

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.

References

https://github.com/TryGhost/Ghost/security/advisories/GHSA-2gx6-7gx2-wwcf

https://github.com/TryGhost/Ghost/releases/tag/v6.54.1

https://github.com/TryGhost/Ghost/pull/29635

https://github.com/TryGhost/Ghost/commit/a8bea3a4ceec4c852b880f4885119453c3d8588e

Details

Source: Mitre, NVD

Published: 2026-08-04

Updated: 2026-08-04

Risk Information

CVSS v2

Base Score: 5.3

Vector: CVSS2#AV:N/AC:H/Au:M/C:N/I:C/A:P

Severity: Medium

CVSS v3

Base Score: 5

Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:L

Severity: Medium