Arbitrary file upload in Ghost - #VU151101
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote user to compromise other staff users' admin sessions.
The vulnerability exists due to unrestricted upload of files with dangerous types in the default local storage adapter when uploading files. A remote user can upload a script file served with a content type derived from its file extension to compromise other staff users' admin sessions.
User interaction is required for a staff user to execute the uploaded script.