Threat Advisory

Ghost Cross-Site Scripting via Universal Import

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in ghost, a package used by GitHub. These vulnerabilities pose a moderate to high risk of exploitation, potentially leading to cross-site scripting, file upload spoofing, and server-side request forgery attacks. Affected versions are not explicitly stated.

CVE-2026-70588 (CVSS 7.5 — High): A cross-site scripting vulnerability exists in the Universal Import feature of Ghost, allowing an attacker to inject malicious code via a crafted import file.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in ghost, a package used by GitHub. These vulnerabilities pose a moderate to high risk of exploitation, potentially leading to cross-site scripting, file upload spoofing, and server-side request forgery attacks. Affected versions are not explicitly stated.

CVE-2026-70588 (CVSS 7.5 — High): A cross-site scripting vulnerability exists in the Universal Import feature of Ghost, allowing an attacker to inject malicious code via a crafted import file.[emaillocker id="1283"]

CVE-2026-53948 (CVSS 8.1 — Critical): An attacker can spoof the Content-Type header of a file upload, potentially leading to arbitrary code execution.

CVE-2026-70589 (CVSS 5.3 — Medium): Archived offers in Ghost can be redeemed by an attacker, potentially leading to unauthorized access.

CVE-2026-53944 (CVSS 8.1 — Critical): Private IP filtering can be bypassed in Ghost, allowing an attacker to make server-side requests to internal services.

CVE-2026-53945 (CVSS 9.0 — Critical): A server-side request forgery vulnerability exists in Ghost's external request handling, potentially leading to arbitrary code execution via DNS rebinding.

CVE-2026-53946 (CVSS 7.5 — High): An attacker can fetch images from a malicious URL using the Mobiledoc image-size feature in Ghost, potentially leading to SSRF attacks.

CVE-2026-70590 (CVSS 8.1 — Critical): A blind password hash disclosure vulnerability exists in the Ghost Admin API, allowing an attacker to obtain sensitive information.

CVE-2026-70591 (CVSS 9.0 — Critical): A server-side request forgery vulnerability exists in Ghost's image fetching feature, potentially leading to arbitrary code execution via SSRF attacks.

CVE-2026-70592 (CVSS 7.5 — High): An attacker can traverse the database backup path in Ghost, potentially leading to unauthorized access.

CVE-2026-70593 (CVSS 8.1 — Critical): A theme upload path traversal vulnerability exists in Ghost, allowing an attacker to upload malicious files.

CVE-2026-70594 (CVSS 5.3 — Medium): Session fixation can occur in the Ghost Admin feature, potentially leading to unauthorized access.

CVE-2026-53947 (CVSS 7.5 — High): A member existence leak vulnerability exists in Ghost's magic link sign-in response, allowing an attacker to obtain sensitive information.

CVE-2026-59817 (CVSS 8.1 — Critical): Paid gift memberships can be obtained at minimal cost via the donations feature in Ghost, potentially leading to financial loss.

RECOMMENDATION:

We recommend you to update Ghost to version 6.54.1.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu