THREAT OPS › Threat News › [GHSA] GHSA-2gx6-7gx2-wwcf (medium) — Ghost: Cross-Site Scripting in Universal Import
[GHSA] GHSA-2gx6-7gx2-wwcf (medium) — Ghost: Cross-Site Scripting in Universal Import
GHSA-2gx6-7gx2-wwcf Severity: medium CVE: CVE-2026-70588
Ghost: Cross-Site Scripting in Universal Import
### Impact
The Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content.
### Vulnerable versions
This vulnerability is present in Ghost from v5.26.0 up to v6.54.0.
### Patches
v6.54.1 contains a fix for this issue.
### How to
Indicators of compromise
- CVE-2026-70588cve
- https://hub.docker.com/_/ghosturl
- https://docs.ghost.org/install/docker#updating-ghosturl
- https://docs.ghost.org/updateurl
- security@ghost.orgemail
Original source: https://github.com/advisories/GHSA-2gx6-7gx2-wwcf