{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ghost-6.22.1-6.63.9/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-105679"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ghost (6.22.1-6.63.9)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","cve-2026-105679"],"_cs_type":"advisory","_cs_vendors":["Ghost Foundation"],"content_html":"\u003cp\u003eGhost, a widely used content management system, contains a security vulnerability (CVE-2026-105679) within its local storage adapter. In affected versions (6.22.1 up to 6.64.0), the application fails to enforce restrictive Content-Type headers when serving uploaded files. Under normal security configurations, platforms serve user-uploaded content with restrictive types to prevent execution. Due to this flaw, files uploaded by staff users are served based on their file extension, enabling an attacker with staff-level privileges to host malicious scripts directly on the application's domain. Successful exploitation allows for the execution of arbitrary JavaScript in the context of other staff users, potentially leading to session hijacking, administrative account compromise, and unauthorized administrative actions within the Ghost instance. Defenders should identify instances running versions within the affected range and prioritize upgrades to v6.64.0 or higher.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in stored cross-site scripting (XSS), which allows an attacker to compromise administrative sessions of staff users. This impacts the integrity and availability of the Ghost instance by enabling malicious actors to perform administrative tasks, modify site content, or extract sensitive session information. This is particularly critical in environments where multiple staff members collaborate on content publishing.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all self-hosted Ghost instances to version 6.64.0 or later to patch CVE-2026-105679.\u003c/li\u003e\n\u003cli\u003eFor Docker-based deployments, pull the latest official Ghost image and follow the standard container update procedures.\u003c/li\u003e\n\u003cli\u003eReview administrative staff access logs for suspicious file upload patterns or unusual activity involving the site storage directory.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, restrict file upload permissions for non-trusted staff accounts until the environment is updated.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:50:47Z","date_published":"2026-10-07T22:50:47Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ghost-xss/","summary":"Ghost versions 6.22.1 through 6.64.0 are vulnerable to stored cross-site scripting due to improper Content-Type handling in the local storage adapter, allowing staff-level users to execute malicious scripts on the site domain.","title":"Stored XSS in Ghost via File Uploads","url":"https://feed.craftedsignal.io/briefs/2026-10-ghost-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Ghost (6.22.1-6.63.9)","version":"https://jsonfeed.org/version/1.1"}