{"id":"CVE-2026-104411","summary":"Ghost 6.22.1 before 6.64.0 Stored XSS via Local Storage File Uploads","details":"Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served with extension-derived content types on the default local storage adapter. Attackers can upload script-bearing files to the site's domain to compromise other staff users' admin sessions.","aliases":["GHSA-gfjp-2p8f-94qv"],"modified":"2026-10-04T02:46:31.097586495Z","published":"2026-10-02T11:37:55.691Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104411.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104411.json"},{"type":"ADVISORY","url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-gfjp-2p8f-94qv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104411"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ghost-6.22.1-before-6.64.0-stored-xss-via-local-storage-file-uploads"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tryghost/ghost","events":[{"introduced":"248fe427883fac0341f268b0a931b25657129dcd"},{"fixed":"2fa451a7dca010016608065ad33bcc58c0043070"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION"],"extracted_events":[{"introduced":"6.22.1"},{"fixed":"6.64.0"}]}}],"versions":["v6.63.0","v6.62.0","v6.61.0","v6.60.0","v6.59.0","v6.58.0","v6.57.1","v6.57.0","v6.56.0","v6.55.0","v6.54.1","v6.54.0","v6.53.0","v6.52.1","v6.52.0","v6.51.0","v6.50.0","v6.49.0","v6.48.0","v6.47.0","v6.46.0","v6.45.0","v6.44.1","v6.44.0","v6.43.1","v6.43.0","v6.42.0","v6.41.1","v6.41.0","v6.40.0","v6.39.0","v6.38.0","v6.37.1","v6.37.0","v6.36.0","v6.35.0","v6.34.0","v6.33.0","v6.32.0","v6.31.0","v6.30.0","v6.29.1","v6.29.0","v6.28.0","v6.27.0","v6.26.0","v6.25.1","v6.25.0","v6.24.0","v6.23.0","v6.22.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104411.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}