XSS via Malicious Portal Preview Links Severity: High (8.8/10) CVE ID: CVE-2026-24778 Weakness: CWE-79 Affected Versions: @tryghost/portal (npm): - Affected: 2.29.1 - 2.51.4, 2.52.0 - 2.57.0 - Patched: 2.51.5, 2.57.1 ghost (npm): - Affected: 5.43.0 - 5.120.4, 6.0.0 - 6.14.0 - Patched: 5.121.0, 6.15.0 Impact An attacker could create a malicious link that, when accessed by an authenticated staff user or member, would execute JavaScript with the victim's permissions, potentially leading to account takeover. Patches For Ghost 5.x users: Upgrade to v5.121.0 or later. For Ghost 6.x users: Upgrade to v6.15.0 or later. For customized or self-hosted Portal versions: Manually rebuild or update to the latest patch version. References Younes Belalia discovered and disclosed this vulnerability responsibly. For More Information Contact: security@ghost.org