GHSA-hqq2-xqr2-fmx2: XSS
Impact
SVG images included in content imports were stored without sanitization. An attacker who convinced an Administrator to import a crafted file could host scripts on the site's domain, possibly resulting in compromise of staff users' admin sessions.
Vulnerable versions
This vulnerability is present in Ghost from v4.0.0 up to v6.65.0.
Patches
v6.67.0 contains a fix for this issue.
How to update
For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.
If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.
References
Ghost thanks Zhixi "Jace" Sun, independent security researcher, for disclosing this vulnerability responsibly.
For more information
If you have any questions or comments about this advisory, email us at security@ghost.org.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/ghostto a version that resolves this vulnerability.Fixed in 6.67.0 - Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.67.0
Event History
Frequently Asked Questions
Which deployments are most exposed to exploitation?
Ghost sites where an Administrator imports content files from untrusted or insufficiently vetted sources are exposed. The issue can allow crafted SVG images in an import to be served with scripts from the site's own domain.
What must an attacker do to exploit this issue?
An attacker must craft a file containing a malicious SVG and persuade an Administrator to import it. No attacker authentication is required, but administrator interaction is required.
What should self-hosted operators do?
Update Ghost to v6.67.0, which contains the fix. Docker-based installations can update the official Ghost image, while Ghost-CLI installations should follow the documented Ghost update process.