CVE-2026-105679High· 7.3▾ TwilightGhost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from executing them. On sites using the default local storage adapter, this restri…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from executing them. On sites using the default local storage adapter, this restriction was not applied, so files uploaded by any staff user were served with a content type derived from their file extension. This could be used to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.64.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105651High· 7.3Ghost is a Node.js content management system
CVE-2026-105649High· 7.3Ghost is a Node.js content management system
CVE-2026-105650High· 8.1Ghost is a Node.js content management system
CVE-2026-105644Medium· 6.8Ghost is a Node.js content management system
CVE-2026-104411High· 7.3Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served with extension-derived content types on the default local storage adapter
CVE-2026-105677High· 7.2Ghost is a Node.js content management system