Input validation error in Ghost - CVE-2026-53948

 

Input validation error in Ghost - CVE-2026-53948

Published: July 30, 2026


Vulnerability identifier: #VU140540
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53948
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to facilitate stored cross-site scripting.

The vulnerability exists due to improper input validation in the Admin API file upload endpoint when processing uploaded files with a client-supplied Content-Type. A remote user can upload a file with a spoofed content type to facilitate stored cross-site scripting.

This issue affects installations using S3 or GCS storage backends and is exploitable on installations that serve uploaded files from the same origin as the site. User interaction is required to visit the uploaded content.


Affected software

Ghost

How to mitigate CVE-2026-53948

Install security update from vendor's website.

Ghost - update to 6.21.1

External References

Related Security Bulletins