CVE-2026-53948Medium· 5.4▾ SunlitGhost: File Upload Content-Type Spoofing
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.1%
0.1% → 0.2%
Insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origin as the site, this could have been used to facilitate stored cross-site scripting against site visitors or staff.
This vulnerability is present in Ghost from v6.19.4 up to v6.21.0.
v6.21.1 contains a fix for this issue.
For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.
If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.
If you have any questions or comments about this advisory, email us at [email protected].
ghost >= 6.19.4, < 6.21.1Upgrade to a patched release:
ghost 6.21.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53947Medium· 5.3Ghost: Member existence leak via magic link sign-in response
CVE-2026-53944Medium· 5.8Ghost: Private IP filtering bypass to make server-side requests to internal services
CVE-2026-53945Medium· 4.0Ghost: Server-side request forgery via DNS rebinding in external request handling
CVE-2026-53946Medium· 5.4Ghost: Mobiledoc image-size fetch SSRF
CVE-2022-28397Critical· 9.8An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file
CVE-2026-70595Medium· 4.0Ghost is a Node.js content management system