SCA: security update for @tryghost/portal, ghost (GHSA-gv6q-2m97-882h)

medium Tenable Cloud Security Plugin ID 437346

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0.0
through 6.14.0, an attacker was able to craft a malicious link that, when accessed by an authenticated
staff user or member, would execute JavaScript with the victim's permissions, potentially leading to
account takeover. Ghost Portal versions 2.29.1 through 2.51.4 and 2.52.0 through 2.57.0 were vulnerable to
this issue. Ghost automatically loads the latest patch of the members Portal component via CDN. For Ghost
5.x users, upgrading to v5.121.0 or later fixes the vulnerability. v5.121.0 loads Portal v2.51.5, which
contains the patch. For Ghost 6.x users, upgrading to v6.15.0 or later fixes the vulnerability. v6.15.0
loads Portal v2.57.1, which contains the patch. For Ghost installations using a customized or self-hosted
version of Portal, it will be necessary to manually rebuild from or update to the latest patch version.
(CVE-2026-24778)

See Also

https://github.com/advisories/GHSA-gv6q-2m97-882h

Plugin Details

Severity: Medium

ID: 437346

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/28/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.42

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2026-24778

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/28/2026

Vulnerability Publication Date: 1/28/2026

Reference Information

CVE: CVE-2026-24778

cwe: CWE-79