CVE-2026-24778: Ghost vulnerable to XSS via malicious Portal preview links
An attacker was able to craft a malicious link that, when accessed by an authenticated staff user or member, would execute JavaScript with the victim’s permissions, potentially leading to account takeover.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-24778 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →