Ghost是Ghost基金会开源的一款内容管理平台。 Ghost 4.0.0版本至6.37.0之前版本存在信息泄露漏洞,该漏洞源于共享缓存层导致的缓存内容被不同访客共享,可能允许未经身份验证的用户发送x-ghost-preview标头改变前端响应,导致缓存投毒。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-53950 | 7.5 HIGH | @tryghost/activitypub: XSS in Ghost's ActivityPub client |
| CVE-2026-53944 | 5.8 MEDIUM | Ghost: Private IP filtering bypass to make server-side requests to internal services |
| CVE-2026-53948 | 5.4 MEDIUM | Ghost: File Upload Content-Type Spoofing |
| CVE-2026-53946 | 5.4 MEDIUM | Ghost: Mobiledoc image-size fetch SSRF |
| CVE-2026-53947 | 5.3 MEDIUM | Ghost: Member existence leak via magic link sign-in response |
| CVE-2026-53949 | 5.3 MEDIUM | Ghost Content API filter bypass reveals private fields |
| CVE-2026-53945 | 4.0 MEDIUM | Ghost: Server-side request forgery via DNS rebinding in external request handling |
No comments yet