CVE-2026-105642

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attacker-controlled website, resulting in arbitrary commands being run on the Ghost server. This issue is fixed in version 6.67.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-05: 210-05
Referenced assets1 URL
By indicator
Full discourse2 posts
  • sy.br1d@rafabd1_

    Eu havia reportado também pro Ghost e eles publicaram hj a CVE-2026-105642 pra falha de RCE envolvendo o librsvg https://t.co/v9QzhGGF5H

    0102171.6K
    1.9K followersView on X
  • Aretiq.AI@AretiqAI

    ARETIQ Daily Vulnerability Bulletin — October 05, 2026 🔴 CRITICAL: CVE-2026-105642 (tryghost/ghost) AAS 12.2 10 vulnerabilities — CRITICAL: 1, HIGH: 9 Full bulletin: https://aretiq.ai/bulletins/2026-10-05/

    0002056
    232 followersView on X

Explore more