{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aghostghost/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-105679"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ghost (6.22.1-6.63.9)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","cve-2026-105679"],"_cs_type":"advisory","_cs_vendors":["Ghost Foundation"],"content_html":"\u003cp\u003eGhost, a widely used content management system, contains a security vulnerability (CVE-2026-105679) within its local storage adapter. In affected versions (6.22.1 up to 6.64.0), the application fails to enforce restrictive Content-Type headers when serving uploaded files. Under normal security configurations, platforms serve user-uploaded content with restrictive types to prevent execution. Due to this flaw, files uploaded by staff users are served based on their file extension, enabling an attacker with staff-level privileges to host malicious scripts directly on the application's domain. Successful exploitation allows for the execution of arbitrary JavaScript in the context of other staff users, potentially leading to session hijacking, administrative account compromise, and unauthorized administrative actions within the Ghost instance. Defenders should identify instances running versions within the affected range and prioritize upgrades to v6.64.0 or higher.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in stored cross-site scripting (XSS), which allows an attacker to compromise administrative sessions of staff users. This impacts the integrity and availability of the Ghost instance by enabling malicious actors to perform administrative tasks, modify site content, or extract sensitive session information. This is particularly critical in environments where multiple staff members collaborate on content publishing.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all self-hosted Ghost instances to version 6.64.0 or later to patch CVE-2026-105679.\u003c/li\u003e\n\u003cli\u003eFor Docker-based deployments, pull the latest official Ghost image and follow the standard container update procedures.\u003c/li\u003e\n\u003cli\u003eReview administrative staff access logs for suspicious file upload patterns or unusual activity involving the site storage directory.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, restrict file upload permissions for non-trusted staff accounts until the environment is updated.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:50:47Z","date_published":"2026-10-07T22:50:47Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ghost-xss/","summary":"Ghost versions 6.22.1 through 6.64.0 are vulnerable to stored cross-site scripting due to improper Content-Type handling in the local storage adapter, allowing staff-level users to execute malicious scripts on the site domain.","title":"Stored XSS in Ghost via File Uploads","url":"https://feed.craftedsignal.io/briefs/2026-10-ghost-xss/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-103266"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ghost (5.2.0 - 6.61.9)","Ghost (\u003c 6.62.0)","Ghost (2.10.0 - 6.62.x)","Ghost (5.8.0 - 6.33.9)","Ghost (0.5.3 - \u003c 6.50.0)","Ghost (6.22.1 \u003c= version \u003c 6.64.0)","Ghost (6.10.3 to \u003c 6.64.0)","Ghost (4.39.0 \u003c= version \u003c 6.64.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xss","application-security","enumeration","api-security","remote-code-execution","ghost","vulnerability","cms"],"_cs_type":"threat","_cs_vendors":["Ghost"],"content_html":"\u003cp\u003eGhost versions 5.2.0 through 6.61.9 are susceptible to an unauthenticated vulnerability within the Stripe Checkout integration. An attacker can exploit this flaw to force an arbitrary paid subscription onto an existing member's account. This process allows the attacker to manipulate the member's profile, specifically the name field. Furthermore, the vulnerability enables the injection of malicious content, which is subsequently embedded into newsletters generated and distributed by the platform to the affected member. Depending on the email client's handling of the injected HTML, this can lead to successful HTML injection or Cross-Site Scripting (XSS) attacks. Defenders should prioritize patching, as this vulnerability allows for unauthorized modification of member data and potential delivery of malicious payloads via trusted communication channels.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to the integrity of member databases and the security of end-user communications. Successful exploitation allows attackers to associate paid subscriptions with arbitrary users and deliver malicious scripts directly to user email inboxes. This can lead to account takeover, theft of user credentials, or malicious redirects when victims interact with the injected content within the newsletter.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Ghost to version 6.62.0 or later to remediate CVE-2026-103266.\u003c/li\u003e\n\u003cli\u003eAudit recent member subscription history and newsletter delivery logs for anomalies associated with unauthorized Stripe checkout activity.\u003c/li\u003e\n\u003cli\u003eImplement stricter input validation on member profile name fields to mitigate the potential impact of HTML and script injection during the patching window.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T14:24:38Z","date_published":"2026-10-01T12:42:24Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ghost-stripe-vuln/","summary":"A vulnerability in Ghost versions 5.2.0 through 6.61.9 allows unauthenticated remote attackers to manipulate Stripe Checkout flows to modify member records and inject malicious content into newsletters.","title":"Unauthenticated Stripe Checkout Manipulation in Ghost","url":"https://feed.craftedsignal.io/briefs/2026-10-ghost-stripe-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}