Multiple security vulnerabilities have been identified in ghost, a package used by GitHub. These vulnerabilities pose a moderate to high risk of exploitation, potentially leading to cross-site scripting, file upload spoofing, and server-side request forgery attacks. Affected versions are not explicitly stated.
CVE-2026-70588 (CVSS 7.5 — High): A cross-site scripting vulnerability exists in the Universal Import feature of Ghost, allowing an attacker to inject malicious code via a crafted import file.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in ghost, a package used by GitHub. These vulnerabilities pose a moderate to high risk of exploitation, potentially leading to cross-site scripting, file upload spoofing, and server-side request forgery attacks. Affected versions are not explicitly stated.
CVE-2026-70588 (CVSS 7.5 — High): A cross-site scripting vulnerability exists in the Universal Import feature of Ghost, allowing an attacker to inject malicious code via a crafted import file.[emaillocker id="1283"]
CVE-2026-53948 (CVSS 8.1 — Critical): An attacker can spoof the Content-Type header of a file upload, potentially leading to arbitrary code execution.
CVE-2026-70589 (CVSS 5.3 — Medium): Archived offers in Ghost can be redeemed by an attacker, potentially leading to unauthorized access.
CVE-2026-53944 (CVSS 8.1 — Critical): Private IP filtering can be bypassed in Ghost, allowing an attacker to make server-side requests to internal services.
CVE-2026-53945 (CVSS 9.0 — Critical): A server-side request forgery vulnerability exists in Ghost's external request handling, potentially leading to arbitrary code execution via DNS rebinding.
CVE-2026-53946 (CVSS 7.5 — High): An attacker can fetch images from a malicious URL using the Mobiledoc image-size feature in Ghost, potentially leading to SSRF attacks.
CVE-2026-70590 (CVSS 8.1 — Critical): A blind password hash disclosure vulnerability exists in the Ghost Admin API, allowing an attacker to obtain sensitive information.
CVE-2026-70591 (CVSS 9.0 — Critical): A server-side request forgery vulnerability exists in Ghost's image fetching feature, potentially leading to arbitrary code execution via SSRF attacks.
CVE-2026-70592 (CVSS 7.5 — High): An attacker can traverse the database backup path in Ghost, potentially leading to unauthorized access.
CVE-2026-70593 (CVSS 8.1 — Critical): A theme upload path traversal vulnerability exists in Ghost, allowing an attacker to upload malicious files.
CVE-2026-70594 (CVSS 5.3 — Medium): Session fixation can occur in the Ghost Admin feature, potentially leading to unauthorized access.
CVE-2026-53947 (CVSS 7.5 — High): A member existence leak vulnerability exists in Ghost's magic link sign-in response, allowing an attacker to obtain sensitive information.
CVE-2026-59817 (CVSS 8.1 — Critical): Paid gift memberships can be obtained at minimal cost via the donations feature in Ghost, potentially leading to financial loss.
We recommend you to update Ghost to version 6.54.1.
The following reports contain further technical details:
[/emaillocker]