Stored XSS in Ghost via File Uploads
Ghost versions 6.22.1 through 6.64.0 are vulnerable to stored cross-site scripting due to improper Content-Type handling in the local storage adapter, allowing staff-level users to execute malicious scripts on the site domain.
CVE search metadata
CVE search record: CVE-2026-105679. Severity: high. CVSS: 7.3. EPSS: 0.24%. KEV: no. Product: Ghost (6.22.1-6.63.9). Brief: Stored XSS in Ghost via File Uploads. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ghost-xss/
Ghost, a widely used content management system, contains a security vulnerability (CVE-2026-105679) within its local storage adapter. In affected versions (6.22.1 up to 6.64.0), the application fails to enforce restrictive Content-Type headers when serving uploaded files. Under normal security configurations, platforms serve user-uploaded content with restrictive types to prevent execution. Due to this flaw, files uploaded by staff users are served based on their file extension, enabling an attacker with staff-level privileges to host malicious scripts directly on the application's domain. Successful exploitation allows for the execution of arbitrary JavaScript in the context of other staff users, potentially leading to session hijacking, administrative account compromise, and unauthorized administrative actions within the Ghost instance. Defenders should identify instances running versions within the affected range and prioritize upgrades to v6.64.0 or higher.
Impact
Successful exploitation results in stored cross-site scripting (XSS), which allows an attacker to compromise administrative sessions of staff users. This impacts the integrity and availability of the Ghost instance by enabling malicious actors to perform administrative tasks, modify site content, or extract sensitive session information. This is particularly critical in environments where multiple staff members collaborate on content publishing.
Recommendation
- Upgrade all self-hosted Ghost instances to version 6.64.0 or later to patch CVE-2026-105679.
- For Docker-based deployments, pull the latest official Ghost image and follow the standard container update procedures.
- Review administrative staff access logs for suspicious file upload patterns or unusual activity involving the site storage directory.
- If immediate patching is not possible, restrict file upload permissions for non-trusted staff accounts until the environment is updated.
Immediate actions
Upgrade Ghost instance to v6.64.0 or later
Mitigations
Upgrade to v6.64.0
CVE-2026-105679