SB2026073063 - Multiple vulnerabilities in Ghost
Published: July 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 9 vulnerabilities.
1) Improper Authorization (CVE-ID: N/A)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to redeem inactive subscription offers.
The vulnerability exists due to improper access control in the offer redemption logic when processing offer redemption requests. A remote attacker can redeem an archived offer to redeem inactive subscription offers.
2) Insufficient Session Expiration (CVE-ID: N/A)
CWE-ID: CWE-613 - Insufficient Session Expiration
CVSSv4: 7.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to hijack an authenticated session.
The vulnerability exists due to improper session expiration in Ghost Admin when handling login requests. A remote attacker can reuse a fixed session identifier to hijack an authenticated session.
Successful exploitation requires another vulnerability on the same domain where Ghost Admin is hosted, and user interaction is required.
3) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to inject arbitrary script code into post content.
The vulnerability exists due to improper neutralization of input during web page generation in the Universal Import feature in Ghost Admin when importing content. A remote privileged user can import specially crafted content to inject arbitrary script code into post content.
4) Path traversal (CVE-ID: N/A)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify files outside the intended upload directory and alter the behavior of the installation.
The vulnerability exists due to path traversal in the theme upload feature when uploading custom themes. A remote privileged user can upload a specially crafted theme to modify files outside the intended upload directory and alter the behavior of the installation.
5) Input validation error (CVE-ID: N/A)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to make limited HTTP requests to hosts in the server's internal network.
The vulnerability exists due to improper input validation in Webmentions functionality when handling user-supplied URLs. A remote attacker can submit a specially crafted request to make limited HTTP requests to hosts in the server's internal network.
No response data is returned to the requester.
6) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper input validation in feature image captions when rendering crafted post content in Ghost Admin. A remote privileged user can create a post with crafted content to escalate privileges.
User interaction is required for another staff user to view the crafted content.
7) Path traversal (CVE-ID: N/A)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to overwrite certain files on the filesystem.
The vulnerability exists due to path traversal in the database backup feature when handling backup operations. A remote privileged user can supply a crafted path to overwrite certain files on the filesystem.
8) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
The vulnerability allows a remote user to perform blind HTTP requests against internal hosts.
The vulnerability exists due to server-side request forgery in the image fetching functionality when processing image fetch requests. A remote privileged user can supply a crafted image URL to perform blind HTTP requests against internal hosts.
This issue could be used to probe open ports on internal hosts.
9) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose password hashes of other staff users.
The vulnerability exists due to improper access control in the Ghost Admin API when handling requests for staff user data. A remote privileged user can access password hash data for other staff users to disclose password hashes of other staff users.
User interaction is required, and successful offline password guessing could lead to account takeover.
Remediation
Install update from vendor's website.
References
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-4wx2-7gvj-qfq3
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-7mpp-r37j-x5wh
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-2gx6-7gx2-wwcf
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-cjc9-q5gf-327p
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-x5mm-wm4g-j5xv
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-pr22-p9rp-2cqv
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-cj62-hvv2-2q5h
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-gcvv-72q8-9v76
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-jm22-3w23-5q7w