CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-944x-pm95-3jpr: Ghost: File Upload Content-Type Spoofing

mediumCVSS 5.4CVE-2026-53948
Impact Insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origin as the site, this could have been used to facilitate stored cross-site scripting against site visitors or staff. Vulnerable versions This vulnerability is present in Ghost from v6.19.4 up to v6.21.0. Patches v6.21.1 contains a fix for this issue. How to update For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here. If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here. For more information If you have any questions or comments about this advisory, email us at security@ghost.org.

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
medium — CVSS 5.4
Published
2026-08-04
Last updated
2026-08-04
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-944x-pm95-3jpr

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-53948coverage & exploitation statusNVD · CVE.org

More from GitHub Security Advisories