THREAT OPS › Threat News › [GHSA] GHSA-pr22-p9rp-2cqv (medium) — Ghost: Cross-Site Scripting in Feature Image Captions
[GHSA] GHSA-pr22-p9rp-2cqv (medium) — Ghost: Cross-Site Scripting in Feature Image Captions
GHSA-pr22-p9rp-2cqv Severity: medium CVE: CVE-2026-70596
Ghost: Cross-Site Scripting in Feature Image Captions
### Impact
An input validation issue allowed any staff user to create a post with content that could be used to hijack another staff user's Ghost Admin session resulting in privilege escalation.
### Vulnerable versions
This vulnerability is present in Ghost from v4.9.0 up to v6.54.0.
Indicators of compromise
- CVE-2026-70596cve
- https://hub.docker.com/_/ghosturl
- https://docs.ghost.org/install/docker#updating-ghosturl
- https://docs.ghost.org/updateurl
- security@ghost.orgemail
Original source: https://github.com/advisories/GHSA-pr22-p9rp-2cqv