Impact
Ghost from version 6.22.1 up to (but not including) 6.64.0 contains a stored cross‑site scripting flaw that lets staff users host JavaScript by uploading files that are served with content types derived from their file extensions. When such a script file is uploaded via the default local storage adapter, other staff members viewing the site will have the script executed in the context of their own browsers, allowing attackers to hijack admin sessions or run arbitrary code as the staff user.
Affected Systems
The vendor TryGhost offers the Ghost CMS product. All releases of Ghost from 6.22.1 through 6.63.x are affected by this flaw. Users of any of those versions should check the version of Ghost they are running and prepare to upgrade to 6.64.0 or newer, which contains the fix.
Risk and Exploitability
With a CVSS score of 8.5, the vulnerability is considered high severity. No EPSS score is available, and the flaw is not listed in CISA’s KEV catalog, which suggests that widespread exploitation is not yet confirmed. Exploitability requires a staff‑level authenticated session to upload the malicious file; after the file is stored, any staff visitor to the site will have the payload executed. The attack vector is local to the site’s domain and relies on the application’s file‑upload functionality, so defenders can mitigate by disabling that feature or filtering uploads.
OpenCVE Enrichment