Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.7 Node.js & npm GHSA-4pvx-fwjj-8gpc CVE-2026-104412 GHSA-gfjp-2p8f-94qv CVE-2026-104411

Three Ghost CMS Vulnerabilities Patched: Stored XSS, Role Privilege Escalation, and SSRF

Ghost has fixed three vulnerabilities affecting staff accounts: a stored XSS flaw via file uploads (CVE-2026-104411), a role-assignment flaw allowing Editors to self-promote staff (CVE-2026-104412), and an SSRF issue in the webhooks feature (CVE-2026-103287). Updating to Ghost 6.64.0 (or 6.27.0 for the SSRF issue) addresses these issues.

AI summary

Three distinct vulnerabilities have been disclosed and fixed in Ghost, the open-source publishing platform. All three require an authenticated staff-level account to exploit, but each allows a malicious or compromised staff user to escalate their impact on a Ghost installation — ranging from hijacking admin sessions to improperly elevating other users' roles or probing internal network resources. Site administrators running affected Ghost versions should review the fixes below and update as appropriate.

Three separate vulnerabilities identified in Ghost

Security researchers identified and Ghost's maintainers fixed three vulnerabilities in the Ghost CMS: a stored cross-site scripting (XSS) issue in the file upload handling for the default local storage adapter (CVE-2026-104411 / GHSA-gfjp-2p8f-94qv), a role-assignment flaw that let Editor and Super Editor accounts assign their own role to other users without proper authorization (CVE-2026-104412 / GHSA-4pvx-fwjj-8gpc), and a server-side request forgery (SSRF) vulnerability in the webhooks feature that allowed staff users to probe internal network hosts (CVE-2026-103287 / GHSA-354h-gmhv-mr9c).

Root causes

The stored XSS issue (CVE-2026-104411) stems from Ghost serving uploaded files with content types derived from their file extension on the default local storage adapter, allowing a staff user to upload a script-bearing file that executes in the context of the site's domain. The role-assignment flaw (CVE-2026-104412) arises from insufficient restriction of staff role assignment logic (CWE-269), permitting Editor and Super Editor accounts to assign their own role to Author and Contributor users despite lacking the required permission. The SSRF issue (CVE-2026-103287, CWE-918) is located in the webhooks feature, where insufficient validation of webhook target requests allows staff users to craft requests that reach internal network resources from the Ghost server.

Why these issues matter

Each vulnerability requires an authenticated staff account, which limits exploitation to users who already have some level of access to a Ghost instance — such as a compromised Author/Contributor account, or a malicious insider. The stored XSS issue (CVE-2026-104411) is the most severe of the three (CVSS 8.5), since it allows a staff user to compromise other staff members' admin sessions by hosting scripts on the site's own domain, potentially escalating a low-privilege compromise into full administrative control. The role-assignment flaw (CVE-2026-104412, CVSS 5.3) breaks the intended staff permission hierarchy, letting Editors grant themselves equal or near-equal privileges to other users without authorization. The SSRF flaw (CVE-2026-103287, CVSS 5.1) could be used by a staff user to reach internal network resources that should not be accessible from the public-facing Ghost server.

Affected versions

CVE-2026-104411 affects Ghost from version 6.22.1 up to (but not including) 6.64.0. CVE-2026-104412 affects Ghost from version 0.5.0 up to (but not including) 6.64.0. CVE-2026-103287 affects Ghost from version 1.18.0 up to (but not including) 6.27.0.

Fixes available

Fixes for CVE-2026-104411 and CVE-2026-104412 are available in Ghost 6.64.0. The fix for CVE-2026-103287 is available in Ghost 6.27.0; installations that update to 6.64.0 would also include this fix, since it supersedes 6.27.0 in the affected range, though the fact package does not explicitly confirm this cumulative relationship beyond each vulnerability's own fixed version.

Recommended action

Administrators of self-hosted Ghost instances should update to Ghost 6.64.0 or later to address all three vulnerabilities. If an immediate update to 6.64.0 is not feasible, updating to at least 6.27.0 addresses the SSRF issue (CVE-2026-103287), but the stored XSS and role-assignment issues would remain unpatched until 6.64.0 is applied. Review staff account access and permissions as a general precaution, since all three vulnerabilities depend on an attacker already holding a staff-level account.

PatchBriefing score

4.7 / 10 · Medium

Official CVSS: 8.5

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

The three vulnerabilities carry different severity levels based on their CVSS 4.0 base scores: CVE-2026-104411 (stored XSS) scores 8.5, reflecting its ability to compromise other staff users' admin sessions through script execution on the site's own domain. CVE-2026-104412 (role-assignment flaw) scores 5.3, and CVE-2026-103287 (SSRF) scores 5.1 — both are lower because they require specific staff privilege levels and have more limited direct impact. None of the three vulnerabilities is listed as known exploited, has a public exploit, or has an associated EPSS score in the fact package. Each requires an authenticated staff account to exploit, which constrains the achievable severity scores despite fixes being available for all three.

Affected versions

ghost ≥ 0.5.0 < 6.64.0
vulnerable
≥ 6.64.0
patched
ghost ≥ 6.22.1 < 6.64.0
vulnerable
≥ 6.64.0
patched
ghost ≥ 1.18.0 < 6.27.0
vulnerable
≥ 6.27.0
patched

Reported fixes

Fixes for CVE-2026-104411 and CVE-2026-104412 are available in Ghost 6.64.0. The fix for CVE-2026-103287 is available in Ghost 6.27.0; installations that update to 6.64.0 would also include this fix, since it supersedes 6.27.0 in the affected range, though the fact package does not explicitly confirm this cumulative relationship beyond each vulnerability's own fixed version.

How this was built

6 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • OSV.dev database
  • OSV.dev database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Three Ghost CMS Vulnerabilities Patched: Stored XSS, Role Privilege Escalation, and SSRF
1 article · 6 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email