Sceawere

Vulnerability Detail

CVE-2026-105679UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ghost File Upload MIME Misconfiguration

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
1h ago
Vendor
TryGhost
Product
Ghost
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from executing them. On sites using the default local storage adapter, this restriction was not applied, so files uploaded by any staff user were served with a content type derived from their file extension. This could be used to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.64.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T20:17:15.107Z",
  "pubdate": "2026-10-05T20:17:15.107Z",
  "executiveSummary": "A security vulnerability exists in Ghost CMS versions 6.22.1 through 6.64.0 involving improper MIME type handling for user-uploaded files when using the local storage adapter.\nThe vulnerability allows for the storage and execution of malicious scripts on the site's domain, effectively bypassing browser-side security restrictions designed to prevent unauthorized script execution.\nAn authenticated staff user can exploit this flaw to upload non-intended file types, which are subsequently served with browser-interpreted MIME types rather than being constrained by security policies.\nThe primary risk involves Cross-Site Scripting (XSS) scenarios, where malicious scripts executed within the context of the site's origin could compromise the admin sessions of other privileged users.\nSuccessful exploitation requires the attacker to possess staff-level access to the Ghost CMS to initiate file uploads.\nThis issue is addressed in version 6.64.0, which enforces consistent content-type restrictions across storage adapters.",
  "technicalDetails": "The vulnerability originates from an inconsistent application of security headers and MIME type enforcement within the Ghost CMS file handling pipeline.\nSpecifically, when configured to use the default local storage adapter, the application fails to restrict the Content-Type header of served files, instead relying on the MIME type derived directly from the uploaded file extension.\nIn secure configurations, content served from an untrusted upload directory should be forced to 'application/octet-stream' or other non-executable types to prevent browser interpretation.\nBy failing to sanitize or override these headers, Ghost permits the hosting of executable content, such as HTML/JavaScript files, on the same domain as the application's administrative interface.\nThe attack flow proceeds as follows: 1. An attacker with staff privileges navigates to the administrative file upload interface. 2. The attacker uploads a crafted script file (e.g., .html or .svg containing malicious JavaScript) with a deceptive extension or content that forces the server to return a browser-executable MIME type. 3. Because the local storage adapter serves these files without adequate content-type restrictions, the server response includes a MIME type that causes the browser to execute the uploaded content upon retrieval. 4. If the attacker convinces an administrative user to access the direct URL of the uploaded file, the script executes within the security context of the Ghost domain.\nThe post-exploitation impact includes the potential for session hijacking, unauthorized administrative actions, or credential theft, as the malicious script can access cookies, local storage, or perform requests on behalf of the victim authenticated session.\nThis vulnerability is restricted to environments utilizing the local storage adapter; however, it represents a significant security misconfiguration in standard deployment architectures.\nThe lack of restrictive MIME-type serving essentially bypasses Content Security Policy (CSP) or other browser-based mitigations that might otherwise be configured to prevent the execution of untrusted scripts."
}
CVE-2026-105679: Ghost File Upload MIME Misconfiguration (HIGH Severity, CVSS: 7.3) | Sceawere