CVE-2026-105679
Ghost: Stored XSS via File Uploads on Local Storage
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from executing them. On sites using the default local storage adapter, this restriction was not applied, so files uploaded by any staff user were served with a content type derived from their file extension. This could be used to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.64.0.
| CWE | CWE-79 CWE-434 |
| Vendor | tryghost |
| Product | ghost |
| Published | Oct 5, 2026 |
| Last Updated | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for tryghost ghost
Be the first to know when new high vulnerabilities affecting tryghost ghost are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
TryGhost / Ghost
>= 6.22.1, < 6.64.0
References
github.com: https://github.com/TryGhost/Ghost/security/advisories/GHSA-gfjp-2p8f-94qv github.com: https://github.com/TryGhost/Ghost/pull/30762 github.com: https://github.com/TryGhost/Ghost/commit/58669d5c8b898f8b69c1287c2779b29ecc7eb918 github.com: https://github.com/TryGhost/Ghost/releases/tag/v6.64.0