
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24778 is a Cross-Site Scripting (XSS) vulnerability in Ghost CMS and its Portal component that allows attackers to craft malicious links which, when clicked by an authenticated staff user or member, execute arbitrary JavaScript with the victim's permissions — potentially leading to account takeover. It was discovered by Younes Belalia and disclosed on January 27, 2026. Affected versions include Ghost 5.43.0 through 5.120.4, Ghost 6.0.0 through 6.14.0, Ghost Portal 2.29.1 through 2.51.4, and Ghost Portal 2.52.0 through 2.57.0. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) per the GitHub Security Advisory (GitHub Advisory, Ghost Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). Two distinct injection points were identified in the Portal component: (1) the portal_signup_terms_html field was rendered via React's dangerouslySetInnerHTML without sanitization in both signup-page.js and offer-page.js, allowing arbitrary HTML/JavaScript injection; and (2) the accent_color/brandColor site setting was interpolated directly into a CSS <style> block without validation, enabling CSS injection that could be leveraged for XSS. The attack requires no privileges to craft but requires user interaction — a victim must click the malicious link while authenticated. The fix introduced DOMPurify-based HTML sanitization (sanitizeHtml()) for signup terms and a hex color validator (validateHexColor()) for brand colors (Ghost Advisory, Patch Commit).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of an authenticated staff user or member session, enabling account takeover, session hijacking, credential theft, and unauthorized access to sensitive Ghost CMS data. Because staff accounts may have administrative privileges, a compromised staff session could result in full site compromise, content manipulation, or exfiltration of subscriber data. Availability is not directly impacted, but confidentiality and integrity are both rated High by the vendor (GitHub Advisory, Ghost Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.02% (6th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
portal_signup_terms_html (e.g., <img src=x onerror=alert('XSS')>) or by crafting a malicious accent_color value that breaks out of the CSS context./ghost/api/admin/users/) not initiated by the legitimate user.Ghost has released patched versions addressing both injection points. For Ghost 5.x users, upgrade to v5.121.0 or later (which loads Portal v2.51.5 containing the fix). For Ghost 6.x users, upgrade to v6.15.0 or later (which loads Portal v2.57.1 containing the fix). Ghost automatically loads the latest patch of the Portal component via CDN, so standard Ghost upgrades are sufficient for most deployments. For installations using a customized or self-hosted version of Portal, manually rebuild from or update to Portal v2.51.5 (5.x branch) or v2.57.1 (6.x branch). As an additional defense-in-depth measure, implement a strict Content Security Policy (CSP) header to limit the impact of any future XSS vulnerabilities (Ghost Advisory, Patch Commit).
The vulnerability was covered by The Hacker Wire shortly after disclosure, noting the XSS-to-account-takeover risk for Ghost CMS users (The Hacker Wire). A technical write-up was published by Infinit Security detailing the XSS vector via malicious Portal preview links (Infinit Security). Community reaction was moderate, with the vulnerability noted as responsibly disclosed by researcher Younes Belalia and promptly patched by the Ghost team (Ghost Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."