SB20260919186 - Multiple vulnerabilities in Ghost
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 vulnerabilities.
1) Arbitrary file upload (CVE-ID: N/A)
CWE-ID: CWE-434 - Unrestricted Upload of File with Dangerous Type
CVSSv4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise other staff users' admin sessions.
The vulnerability exists due to unrestricted upload of files with dangerous types in the default local storage adapter when uploading files. A remote user can upload a script file served with a content type derived from its file extension to compromise other staff users' admin sessions.
User interaction is required for a staff user to execute the uploaded script.
2) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to assign their own role to Author and Contributor users.
The vulnerability exists due to incorrect authorization in Ghost staff user role assignment functionality when assigning roles to staff users. A remote user can assign their own Editor or Super Editor role to Author and Contributor users to assign their own role to Author and Contributor users.
3) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to compromise other staff users' admin sessions.
The vulnerability exists due to improper neutralization of input during web page generation in bookmark card images when creating bookmark cards that fetch externally hosted non-image files. A remote user can create a bookmark card that stores an arbitrary HTML file as an icon or thumbnail to compromise other staff users' admin sessions.
User interaction is required.
4) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary scripts in the Ghost editor, on published sites, and in newsletter emails.
The vulnerability exists due to improper neutralization of input during web page generation in oEmbed photo responses when embedding a URL from an attacker-controlled website. A remote attacker can provide a URL that causes untrusted scripts to be stored in post content to execute arbitrary scripts in the Ghost editor, on published sites, and in newsletter emails.
User interaction is required to render the stored post content.
5) Observable discrepancy (CVE-ID: N/A)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to determine the relative ordering of other staff users' hashed passwords.
The vulnerability exists due to an observable discrepancy in the Ghost Admin API when querying staff user information. A remote user can query staff user information to determine the relative ordering of other staff users' hashed passwords.
The issue does not directly disclose password hashes and does not provide a practical path to recovering a password.
6) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: N/A)
CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in the Ghost Admin API staff invites feature when viewing staff invites. A remote user can obtain a pending invite's secret token and accept an invite for a higher-privilege role to escalate privileges.
7) Path traversal (CVE-ID: N/A)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in Ghost theme translation file loading when processing a locale setting. A remote privileged user can specify a path traversal sequence in the locale setting to read JSON files outside the active theme directory and disclose sensitive information.
8) Code Injection (CVE-ID: N/A)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code on the server.
The vulnerability exists due to improper control of code generation in the theme translation file loader when loading translation files from a crafted theme. A remote privileged user can provide a crafted theme to execute arbitrary code on the server.
Remediation
Install update from vendor's website.
References
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-gfjp-2p8f-94qv
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-4pvx-fwjj-8gpc
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-347q-26qq-h2p6
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-v3xr-g6p2-fvgv
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-53vv-xm9f-mm82
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-v6q3-xqxm-6f5v
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-m382-6jw4-fmp6
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-jj74-hc2q-xrvm