CVE-2026-105679
Received Received - Intake

Improper File Content-Type Handling in Ghost CMS

Vulnerability report for CVE-2026-105679, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from executing them. On sites using the default local storage adapter, this restriction was not applied, so files uploaded by any staff user were served with a content type derived from their file extension. This could be used to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.64.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
TryGhost Ghost >= 6.22.1, < 6.64.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Ghost CMS versions 6.22.1 to 6.64.0. It involves improper handling of content types for uploaded files when using the default local storage adapter. Files uploaded by staff users were served with content types matching their extensions, allowing malicious scripts to be hosted on the site's domain. This could lead to stored cross-site scripting (XSS) attacks, potentially compromising admin sessions of other staff users.

Detection Guidance

To detect this vulnerability, check if your Ghost CMS version is between 6.22.1 and 6.64.0. Run the command: ghost version. If the version falls within this range, the system is vulnerable. Additionally, inspect HTTP response headers for uploaded files to verify if they lack 'X-Content-Type-Options: nosniff' or serve executable content types like text/html for files such as .js or .svg.

Impact Analysis

If you use Ghost CMS versions 6.22.1 to 6.64.0 with the default local storage adapter, an attacker with staff access could upload malicious files. These files could be executed in other users' browsers, leading to session hijacking, unauthorized actions, or data theft. The impact includes potential compromise of admin accounts and sensitive data exposure.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, which may violate GDPR's data protection requirements or HIPAA's safeguards for protected health information. A successful XSS attack could expose sensitive user data, resulting in non-compliance with these regulations and potential legal consequences.

Mitigation Strategies

Immediately update Ghost CMS to version 6.64.0 or later. For Docker installations, pull the latest image and redeploy. For Ghost-CLI, run: ghost update. Ensure the 'X-Content-Type-Options: nosniff' header is present in responses for uploaded files. Review and remove any suspicious uploaded files with executable extensions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105679. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart