Sceawere
Vulnerability Detail
CVE-2026-104411UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ghost Stored XSS via File Upload
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 11h ago
- Vendor
- TryGhost
- Product
- Ghost
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served with extension-derived content types on the default local storage adapter. Attackers can upload script-bearing files to the site's domain to compromise other staff users' admin sessions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-02T12:17:10.690Z",
"pubdate": "2026-10-02T12:17:10.690Z",
"executiveSummary": "Ghost versions 6.22.1 through 6.63.1 are susceptible to a stored cross-site scripting (XSS) vulnerability facilitated by the default local storage adapter. This security flaw enables authenticated staff users to upload arbitrary files that are served by the application using content types derived directly from the file extension. By injecting malicious scripts into these files, an attacker can execute arbitrary JavaScript within the context of other staff users' sessions when those users access the hosted file. This vulnerability poses a significant risk to the administrative integrity of the Ghost platform, as a successful exploit permits session hijacking, unauthorized actions on behalf of the victim, and potential privilege escalation within the Ghost admin interface. Exploitation requires authenticated access with permissions sufficient to upload files to the platform's storage adapter. The vulnerability is fundamentally rooted in the insecure handling of MIME type determination for user-uploaded content, which circumvents standard security protections intended to prevent the execution of untrusted scripts in the application's origin.",
"technicalDetails": "The vulnerability resides within the file handling mechanism of the Ghost default local storage adapter. The root cause is the reliance on file extensions to determine the Content-Type header when serving uploaded files. By failing to validate the file content against a strict allowlist or sanitizing the MIME type during the upload process, the application allows the storage of files containing malicious payloads that are rendered as executable scripts by the browser.\nThe attack flow commences when an authenticated attacker, holding appropriate staff privileges, uploads a file (e.g., an HTML or SVG file containing an XSS payload) to the Ghost instance via the admin interface. Because the local storage adapter serves these files using a Content-Type derived from the extension, the browser interprets the file as a valid script or document rather than an opaque binary download. When an unsuspecting administrator or other staff user visits the direct URL of the uploaded file, the browser executes the embedded JavaScript within the security context (origin) of the Ghost installation.\nThe exploitation of this vulnerability is highly effective for account takeover. Since the script executes within the same origin as the Ghost admin panel, the malicious payload can access session cookies, localStorage, and sessionStorage. An attacker can leverage this access to exfiltrate sensitive data, perform administrative actions (such as creating new admin accounts or modifying site configuration), or redirect the victim to an attacker-controlled domain. The vulnerability is persistent, as the file remains stored on the server and is accessible to anyone who obtains or guesses the file path.\nThe scope of impact is limited to the domain where the Ghost application is hosted. Because modern browsers enforce the Same-Origin Policy (SOP), the execution of these scripts directly compromises the victim's authenticated state on that specific domain. This vulnerability is particularly critical for multi-user installations where trust between staff members might be assumed, as it provides a vector for lateral movement and administrative compromise without requiring direct access to the underlying server operating system."
}