Cross-site scripting in Ghost - CVE-2026-53943

 

Cross-site scripting in Ghost - CVE-2026-53943

Published: July 30, 2026


Vulnerability identifier: #VU140535
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-53943
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary script in victims' browsers and compromise staff user accounts.

The vulnerability exists due to improper neutralization of request-specific content in the frontend when processing requests with an x-ghost-preview header behind a shared caching layer. A remote attacker can send a specially crafted request with an x-ghost-preview header to execute arbitrary script in victims' browsers and compromise staff user accounts.

Exploitation requires a shared caching configuration that serves cached frontend responses across different visitors, and staff account exposure occurs only when the frontend and admin panel are hosted on the same domain.


Affected software

Ghost

How to mitigate CVE-2026-53943

Install security update from vendor's website.

Ghost - update to 6.37.0

External References

Related Security Bulletins