<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aghostghost/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:50:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aghostghost/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Ghost via File Uploads</title><link>https://feed.craftedsignal.io/briefs/2026-10-ghost-xss/</link><pubDate>Wed, 07 Oct 2026 22:50:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ghost-xss/</guid><description>Ghost versions 6.22.1 through 6.64.0 are vulnerable to stored cross-site scripting due to improper Content-Type handling in the local storage adapter, allowing staff-level users to execute malicious scripts on the site domain.</description><content:encoded><![CDATA[<p>Ghost, a widely used content management system, contains a security vulnerability (CVE-2026-105679) within its local storage adapter. In affected versions (6.22.1 up to 6.64.0), the application fails to enforce restrictive Content-Type headers when serving uploaded files. Under normal security configurations, platforms serve user-uploaded content with restrictive types to prevent execution. Due to this flaw, files uploaded by staff users are served based on their file extension, enabling an attacker with staff-level privileges to host malicious scripts directly on the application's domain. Successful exploitation allows for the execution of arbitrary JavaScript in the context of other staff users, potentially leading to session hijacking, administrative account compromise, and unauthorized administrative actions within the Ghost instance. Defenders should identify instances running versions within the affected range and prioritize upgrades to v6.64.0 or higher.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in stored cross-site scripting (XSS), which allows an attacker to compromise administrative sessions of staff users. This impacts the integrity and availability of the Ghost instance by enabling malicious actors to perform administrative tasks, modify site content, or extract sensitive session information. This is particularly critical in environments where multiple staff members collaborate on content publishing.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all self-hosted Ghost instances to version 6.64.0 or later to patch CVE-2026-105679.</li>
<li>For Docker-based deployments, pull the latest official Ghost image and follow the standard container update procedures.</li>
<li>Review administrative staff access logs for suspicious file upload patterns or unusual activity involving the site storage directory.</li>
<li>If immediate patching is not possible, restrict file upload permissions for non-trusted staff accounts until the environment is updated.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>cve-2026-105679</category></item><item><title>Unauthenticated Stripe Checkout Manipulation in Ghost</title><link>https://feed.craftedsignal.io/briefs/2026-10-ghost-stripe-vuln/</link><pubDate>Thu, 01 Oct 2026 12:42:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ghost-stripe-vuln/</guid><description>A vulnerability in Ghost versions 5.2.0 through 6.61.9 allows unauthenticated remote attackers to manipulate Stripe Checkout flows to modify member records and inject malicious content into newsletters.</description><content:encoded><![CDATA[<p>Ghost versions 5.2.0 through 6.61.9 are susceptible to an unauthenticated vulnerability within the Stripe Checkout integration. An attacker can exploit this flaw to force an arbitrary paid subscription onto an existing member's account. This process allows the attacker to manipulate the member's profile, specifically the name field. Furthermore, the vulnerability enables the injection of malicious content, which is subsequently embedded into newsletters generated and distributed by the platform to the affected member. Depending on the email client's handling of the injected HTML, this can lead to successful HTML injection or Cross-Site Scripting (XSS) attacks. Defenders should prioritize patching, as this vulnerability allows for unauthorized modification of member data and potential delivery of malicious payloads via trusted communication channels.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a significant risk to the integrity of member databases and the security of end-user communications. Successful exploitation allows attackers to associate paid subscriptions with arbitrary users and deliver malicious scripts directly to user email inboxes. This can lead to account takeover, theft of user credentials, or malicious redirects when victims interact with the injected content within the newsletter.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of Ghost to version 6.62.0 or later to remediate CVE-2026-103266.</li>
<li>Audit recent member subscription history and newsletter delivery logs for anomalies associated with unauthorized Stripe checkout activity.</li>
<li>Implement stricter input validation on member profile name fields to mitigate the potential impact of HTML and script injection during the patching window.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>web-vulnerability</category><category>xss</category><category>application-security</category><category>enumeration</category><category>api-security</category><category>remote-code-execution</category><category>ghost</category><category>vulnerability</category><category>cms</category></item></channel></rss>