CVE-2026-103277 UNKNOWN

CVE-2026-103277

Published: 2026-10-01

Description

Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in the context of a staff user's admin session, potentially compromising administrative access.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…