<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Ghost (6.22.1-6.63.9) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ghost-6.22.1-6.63.9/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:50:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ghost-6.22.1-6.63.9/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Ghost via File Uploads</title><link>https://feed.craftedsignal.io/briefs/2026-10-ghost-xss/</link><pubDate>Wed, 07 Oct 2026 22:50:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ghost-xss/</guid><description>Ghost versions 6.22.1 through 6.64.0 are vulnerable to stored cross-site scripting due to improper Content-Type handling in the local storage adapter, allowing staff-level users to execute malicious scripts on the site domain.</description><content:encoded><![CDATA[<p>Ghost, a widely used content management system, contains a security vulnerability (CVE-2026-105679) within its local storage adapter. In affected versions (6.22.1 up to 6.64.0), the application fails to enforce restrictive Content-Type headers when serving uploaded files. Under normal security configurations, platforms serve user-uploaded content with restrictive types to prevent execution. Due to this flaw, files uploaded by staff users are served based on their file extension, enabling an attacker with staff-level privileges to host malicious scripts directly on the application's domain. Successful exploitation allows for the execution of arbitrary JavaScript in the context of other staff users, potentially leading to session hijacking, administrative account compromise, and unauthorized administrative actions within the Ghost instance. Defenders should identify instances running versions within the affected range and prioritize upgrades to v6.64.0 or higher.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in stored cross-site scripting (XSS), which allows an attacker to compromise administrative sessions of staff users. This impacts the integrity and availability of the Ghost instance by enabling malicious actors to perform administrative tasks, modify site content, or extract sensitive session information. This is particularly critical in environments where multiple staff members collaborate on content publishing.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all self-hosted Ghost instances to version 6.64.0 or later to patch CVE-2026-105679.</li>
<li>For Docker-based deployments, pull the latest official Ghost image and follow the standard container update procedures.</li>
<li>Review administrative staff access logs for suspicious file upload patterns or unusual activity involving the site storage directory.</li>
<li>If immediate patching is not possible, restrict file upload permissions for non-trusted staff accounts until the environment is updated.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>cve-2026-105679</category></item></channel></rss>