Input validation error in Ghost - CVE-2026-53948
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to facilitate stored cross-site scripting.
The vulnerability exists due to improper input validation in the Admin API file upload endpoint when processing uploaded files with a client-supplied Content-Type. A remote user can upload a file with a spoofed content type to facilitate stored cross-site scripting.
This issue affects installations using S3 or GCS storage backends and is exploitable on installations that serve uploaded files from the same origin as the site. User interaction is required to visit the uploaded content.