VDB
Sign up
HIGH8.8

GHSA-gv6q-2m97-882h

Ghost vulnerable to XSS via malicious Portal preview links

Quick fix

GHSA-gv6q-2m97-882h — ghost: upgrade to the fixed version with the command below.

npm install ghost@5.121.0

Details

### Impact An attacker was able to craft a malicious link that, when accessed by an authenticated staff user or member, would execute JavaScript with the victim's permissions, potentially leading to account takeover.

### Vulnerable versions This vulnerability is present in Ghost versions: - v5.43.0 to v5.120.4 - v6.0.0 to v6.14.0

As well as in Portal versions: - v2.29.1 to v2.51.4 - v2.52.0 to v2.57.0

### Patches Ghost automatically loads the latest patch of the members Portal component via CDN. Therefore: - For Ghost 5.x users, upgrading to v5.121.0 or later fixes the vulnerability (loads Portal v2.51.5, which contains the patch) - For Ghost 6.x users, upgrading to v6.15.0 or later fixes the vulnerability (loads Portal v2.57.1, which contains the patch)

For Ghost installations using a customised or self-hosted version of Portal, it will be necessary to manually rebuild from or update to the latest patch version.

### References Ghost thanks Younes Belalia for discovering and disclosing this vulnerability responsibly.

### For more information If users have any questions or comments about this advisory, email Ghost at [security@ghost.org](mailto:security@ghost.org).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ghost
Introduced in: 5.43.0Fixed in: 5.121.0
Fixnpm install ghost@5.121.0
npm/@tryghost/portal
Introduced in: 2.29.1Fixed in: 2.51.5
Fixnpm install @tryghost/portal@2.51.5
npm/@tryghost/portal
Introduced in: 2.52.0Fixed in: 2.57.1
Fixnpm install @tryghost/portal@2.57.1
npm/ghost
Introduced in: 6.0.0Fixed in: 6.15.0
Fixnpm install ghost@6.15.0

References