Description
Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served with extension-derived content types on the default local storage adapter. Attackers can upload script-bearing files to the site's domain to compromise other staff users' admin sessions.
Published: 2026-10-02
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting leading to staff session hijack
Action: Immediate Patch
AI Analysis

Impact

Ghost from version 6.22.1 up to (but not including) 6.64.0 contains a stored cross‑site scripting flaw that lets staff users host JavaScript by uploading files that are served with content types derived from their file extensions. When such a script file is uploaded via the default local storage adapter, other staff members viewing the site will have the script executed in the context of their own browsers, allowing attackers to hijack admin sessions or run arbitrary code as the staff user.

Affected Systems

The vendor TryGhost offers the Ghost CMS product. All releases of Ghost from 6.22.1 through 6.63.x are affected by this flaw. Users of any of those versions should check the version of Ghost they are running and prepare to upgrade to 6.64.0 or newer, which contains the fix.

Risk and Exploitability

With a CVSS score of 8.5, the vulnerability is considered high severity. No EPSS score is available, and the flaw is not listed in CISA’s KEV catalog, which suggests that widespread exploitation is not yet confirmed. Exploitability requires a staff‑level authenticated session to upload the malicious file; after the file is stored, any staff visitor to the site will have the payload executed. The attack vector is local to the site’s domain and relies on the application’s file‑upload functionality, so defenders can mitigate by disabling that feature or filtering uploads.

Generated by OpenCVE AI on October 2, 2026 at 12:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Ghost to version 6.64.0 or later, which removes the insecure storage handling.
  • If a patch cannot be applied immediately, disable or restrict the local storage file‑upload functionality for staff users and enforce strict MIME type validation for uploaded files.
  • Monitor the site for any unexpected script files stored in the local storage and remove them, then enforce a security review of file‑upload handling to prevent future similar flaws.

Generated by OpenCVE AI on October 2, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served with extension-derived content types on the default local storage adapter. Attackers can upload script-bearing files to the site's domain to compromise other staff users' admin sessions.
Title Ghost 6.22.1 before 6.64.0 Stored XSS via Local Storage File Uploads
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-79
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:37:55.691Z

Reserved: 2026-10-02T00:44:44.528Z

Link: CVE-2026-104411

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:10.690

Modified: 2026-10-02T12:17:10.690

Link: CVE-2026-104411

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T12:30:20Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')