CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-53948

mediumCVSS 5.4covered by 1 sourcefirst seen 2026-08-04
Impact Insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origin as the site, this could have been used to facilitate stored cross-site scripting against site visitors or staff. Vulnerable versions This vulnerability is present in Ghost from v6.19.4 up to v6.21.0. Patches v6.21.1 contains a fix for this issue. How to update For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here. If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here. For more information If you have any questions or comments about this advisory, email us at security@ghost.org.

⚡ Watch CVE-2026-53948

Get an email if CVE-2026-53948 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-53948

CVE.org record

Embed the live status

CVE-2026-53948 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-53948 status](https://www.csirts.com/badge/CVE-2026-53948)](https://www.csirts.com/cve/CVE-2026-53948)