THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-944x-pm95-3jpr (medium) — Ghost: File Upload Content-Type Spoofing

[GHSA] GHSA-944x-pm95-3jpr (medium) — Ghost: File Upload Content-Type Spoofing

highgithub_advisoriesPublished 2026-08-04

GHSA-944x-pm95-3jpr Severity: medium CVE: CVE-2026-53948

Ghost: File Upload Content-Type Spoofing

### Impact

Insufficient validation of the client-supplied `Content-Type` on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origin as th

Indicators of compromise

Original source: https://github.com/advisories/GHSA-944x-pm95-3jpr